Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

52 advisories

Loading
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) High
CVE-2026-59935 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
Denial of Service in pyasn1 via Unbounded Recursion High
CVE-2026-30922 was published for pyasn1 (pip) Mar 17, 2026
romanticpragmatism Credited to romanticpragmatism
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service Moderate
CVE-2026-59203 was published for pillow (pip) Jul 20, 2026
jiagongzheng-stack Credited to jiagongzheng-stack
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS High
GHSA-xf7x-x43h-rpqh was published for json-repair (pip) Jul 13, 2026
pypdf: Possible infinite loop when processing threads/articles in writer Moderate
CVE-2026-54651 was published for pypdf (pip) Jul 9, 2026
k0w4lzk1 Credited to k0w4lzk1 and stefan6419846 stefan6419846 stefan6419846
Python Liquid: Infinite loop when parsing malformed `{% case %}` tags Moderate
CVE-2026-55865 was published for python-liquid (pip) Jun 19, 2026
Nuhiat-Arefin Credited to Nuhiat-Arefin
pypdf: Possible infinite loop when processing outlines/bookmarks in writer Moderate
CVE-2026-54531 was published for pypdf (pip) Jun 16, 2026
SagDeap Credited to SagDeap and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction Moderate
CVE-2026-54530 was published for pypdf (pip) Jun 16, 2026
SagDeap Credited to SagDeap and stefan6419846 stefan6419846 stefan6419846
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic Moderate
CVE-2021-29510 was published for pydantic (pip) May 13, 2021
nina-j Credited to nina-j and bluetech bluetech bluetech
Pillow has a PDF Parsing Trailer Infinite Loop (DoS) Moderate
CVE-2026-42310 was published for pillow (pip) May 4, 2026
kexinoh Credited to kexinoh
justhtml introduces denial-of-service hardening Low
GHSA-r8cj-3554-33mr was published for justhtml (pip) May 8, 2026
EmilStenstrom Credited to EmilStenstrom
justhtml has sanitization bypass in custom policies and programmatic DOM Moderate
GHSA-vrx2-77f2-ww34 was published for justhtml (pip) Apr 22, 2026
EmilStenstrom Credited to EmilStenstrom
pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream Moderate
CVE-2026-33699 was published for pypdf (pip) Mar 25, 2026
kejcao Credited to kejcao and stefan6419846 stefan6419846 stefan6419846
Denial of service via non-terminating SYLT frame parsing loop in tinytag Moderate
CVE-2026-32889 was published for tinytag (pip) Mar 19, 2026
kq5y Credited to kq5y and mathiascode mathiascode mathiascode
vmfunc Credited to vmfunc and bwoodsend bwoodsend bwoodsend
rampageservices Credited to rampageservices
LlamaIndex Improper Handling of Exceptional Conditions vulnerability High
CVE-2024-12704 was published for llama-index-core (pip) Mar 20, 2025
fossilet Credited to fossilet
pypdf has a possible infinite loop when processing TreeObject Moderate
CVE-2026-27024 was published for pypdf (pip) Feb 18, 2026
CheonWoong-Park Credited to CheonWoong-Park and stefan6419846 stefan6419846 stefan6419846
pypdf has possible Infinite Loop when processing outlines/bookmarks Moderate
CVE-2026-24688 was published for pypdf (pip) Jan 26, 2026
JoakimBulow Credited to JoakimBulow and stefan6419846 stefan6419846 stefan6419846
AIOHTTP vulnerable to DoS when bypassing asserts Moderate
CVE-2025-69227 was published for aiohttp (pip) Jan 5, 2026
ThomasRinsma Credited to ThomasRinsma, Dreamsorcerer, and bdraco Dreamsorcerer Dreamsorcerer
bdraco bdraco
aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests High
CVE-2024-30251 was published for aiohttp (pip) May 3, 2024
bytehope Credited to bytehope and Dreamsorcerer Dreamsorcerer Dreamsorcerer
FastChat Uncontrolled Resource Consumption vulnerability High
CVE-2024-10907 was published for fschat (pip) Mar 20, 2025
DB-GPT Uncontrolled Resource Consumption vulnerability High
CVE-2024-10829 was published for dbgpt (pip) Mar 20, 2025
ProTip! Advisories are also available from the GraphQL API