Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

807 advisories

Loading
Mermaid XY Charts are vulnerable to an infinite loop DoS Moderate
CVE-2026-71436 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
nanoid: custom generators can loop indefinitely when size is zero High
CVE-2026-67213 was published for nanoid (npm) Jul 29, 2026
ai Credited to ai
nanoid: non-secure generators can loop indefinitely with negative size High
CVE-2026-67214 was published for nanoid (npm) Jul 29, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments Moderate
CVE-2026-55595 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) High
CVE-2026-59935 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang High
CVE-2026-59901 was published for io.netty:netty-codec (Maven) Jul 22, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS High
CVE-2026-59879 was published for immutable (npm) Jul 21, 2026
mateuszismyname Credited to mateuszismyname
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service Moderate
CVE-2026-59203 was published for pillow (pip) Jul 20, 2026
jiagongzheng-stack Credited to jiagongzheng-stack
protobufjs: Denial of Service via infinite loop in .proto option parsing Moderate
CVE-2026-59877 was published for protobufjs (npm) Jul 20, 2026
bilerden Credited to bilerden
node-tar: Negative tar entry size causes infinite loop in archive replace High
CVE-2026-59874 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
ProTip! Advisories are also available from the GraphQL API