GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
807 advisories
Filter by severity
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on...
High
Unreviewed
CVE-2026-8798
was published
Aug 8, 2026
image-size: ICNS parser allows denial of service through an infinite loop
High
CVE-2025-71330
was published
for
image-size
(npm)
Jun 10, 2026
image-size: JXL and HEIF parsers allow denial of service through infinite loops
High
CVE-2025-71329
was published
for
image-size
(npm)
Jun 10, 2026
nanoid: non-secure generators can loop indefinitely with negative size
High
CVE-2026-67214
was published
for
nanoid
(npm)
Jul 29, 2026
nanoid: custom generators can loop indefinitely when size is zero
High
CVE-2026-67213
was published
for
nanoid
(npm)
Jul 29, 2026
Mermaid XY Charts are vulnerable to an infinite loop DoS
Moderate
CVE-2026-71436
was published
for
mermaid
(npm)
Aug 6, 2026
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
High
CVE-2026-54904
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
A flaw was found in libkcapi. A local attacker can influence an application that uses the...
Moderate
Unreviewed
CVE-2026-71227
was published
Aug 5, 2026
facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body...
High
Unreviewed
CVE-2026-66730
was published
Jul 27, 2026
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
Moderate
CVE-2026-68499
was published
for
re2
(npm)
Jul 31, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go,...
High
Unreviewed
CVE-2026-43871
was published
Jul 27, 2026
In the Linux kernel, the following vulnerability has been resolved:
bonding: prevent potential...
High
Unreviewed
CVE-2026-23451
was published
Apr 3, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
High
CVE-2026-59935
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
High
Unreviewed
CVE-2026-56852
was published
Jul 21, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote...
High
Unreviewed
CVE-2026-4890
was published
May 11, 2026
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an...
High
Unreviewed
CVE-2026-64611
was published
Jul 23, 2026
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
High
CVE-2026-59901
was published
for
io.netty:netty-codec
(Maven)
Jul 22, 2026
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication...
Low
Unreviewed
CVE-2026-59849
was published
Jul 21, 2026
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer...
High
Unreviewed
CVE-2026-64834
was published
Jul 22, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
ProTip!
Advisories are also available from the
GraphQL API