GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
300 advisories
Filter by severity
AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
High
GHSA-rvv3-g6hj-g44x
was published
for
AutoMapper
(NuGet)
Mar 13, 2026
flatted vulnerable to unbounded recursion DoS in parse() revive phase
High
CVE-2026-32141
was published
for
flatted
(npm)
Mar 13, 2026
ImageMagick: MSL - Stack overflow in ProcessMSLScript
Moderate
CVE-2026-25971
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Mar 12, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2...
High
Unreviewed
CVE-2026-1069
was published
Mar 11, 2026
xgrammar vulnerable to DoS via multi-layer nesting
High
CVE-2026-25048
was published
for
xgrammar
(pip)
Mar 5, 2026
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
High
CVE-2026-3520
was published
for
multer
(npm)
Mar 5, 2026
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
High
CVE-2026-27601
was published
for
underscore
(npm)
Mar 3, 2026
A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal...
Moderate
Unreviewed
CVE-2026-3385
was published
Mar 1, 2026
A security vulnerability has been detected in aardappel lobster up to 2025.4. This impacts the...
Moderate
Unreviewed
CVE-2026-2887
was published
Feb 21, 2026
mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and...
Moderate
Unreviewed
CVE-2025-65519
was published
Feb 18, 2026
A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09....
High
Unreviewed
CVE-2025-70957
was published
Feb 14, 2026
A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10....
High
Unreviewed
CVE-2025-70955
was published
Feb 14, 2026
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce...
High
Unreviewed
CVE-2026-1849
was published
Feb 10, 2026
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix recvmsg()...
Moderate
Unreviewed
CVE-2026-23066
was published
Feb 4, 2026
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12...
Moderate
Unreviewed
CVE-2025-36001
was published
Jan 31, 2026
Withdrawn Advisory: eslint has a Stack Overflow when serializing objects with circular references
Moderate
CVE-2025-50537
was published
for
eslint
(npm)
Jan 26, 2026
•
withdrawn
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions...
Low
Unreviewed
CVE-2026-0989
was published
Jan 15, 2026
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability...
Moderate
Unreviewed
CVE-2026-0990
was published
Jan 15, 2026
ImageMagick's failure to limit MVG mutual causes Stack Overflow
Moderate
CVE-2025-68950
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 30, 2025
ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack
Moderate
CVE-2025-68618
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 30, 2025
Duplicate Advisory: Nodemailer is vulnerable to DoS through Uncontrolled Recursion
Moderate
GHSA-46j5-6fg5-4gv3
was published
for
nodemailer
(npm)
Dec 18, 2025
•
withdrawn
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by...
Low
Unreviewed
CVE-2025-67899
was published
Dec 15, 2025
Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all...
High
Unreviewed
CVE-2025-59789
was published
Dec 1, 2025
node-forge has ASN.1 Unbounded Recursion
High
CVE-2025-66031
was published
for
node-forge
(npm)
Nov 26, 2025
ProTip!
Advisories are also available from the
GraphQL API