GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,076
Erlang
29
GitHub Actions
19
Go
1,897
Maven
5,000+
npm
3,630
NuGet
638
pip
3,244
Pub
10
RubyGems
862
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
65 advisories
Filter by severity
Regular Expression Denial of Service in braces
Low
GHSA-g95f-p29q-9xw4
was published
for
braces
(npm)
Jun 6, 2019
Denial of Service in apostrophe
Low
GHSA-pv6r-vchh-cxg9
was published
for
apostrophe
(npm)
Sep 3, 2020
Memory exhaustion in http4s-async-http-client with large or malicious compressed responses
Low
GHSA-8hxh-r6f7-jf45
was published
for
org.http4s:http4s-async-http-client_2.12
(Maven)
Oct 16, 2020
Regular Expression Denial of Service in markdown
Low
GHSA-wx77-rp39-c6vg
was published
for
markdown
(npm)
Sep 4, 2020
Regex denial of service vulnerability in codesample plugin
Low
GHSA-h96f-fc7c-9r55
was published
for
tinymce
(npm)
Jan 6, 2021
Denial of Service via Cache Flooding
Low
GHSA-p68v-frgx-4rjp
was published
for
shopware/core
(Composer)
Oct 19, 2020
Import loops in account imports, nats-server DoS
Low
GHSA-gwj5-3vfq-q992
was published
for
github.com/nats-io/nats-server/v2
(Go)
May 21, 2021
ircdkit vulnerable to Denial of Service due to unhandled connection end event
Low
GHSA-f7r3-p866-q9qr
was published
for
ircdkit
(npm)
Jun 3, 2019
An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel...
Low
Unreviewed
CVE-2020-12655
was published
May 24, 2022
ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is...
Low
Unreviewed
CVE-2020-6867
was published
May 24, 2022
EnumStringValues vulnerable to Uncontrolled Resource Consumption
Low
CVE-2020-36620
was published
for
EnumStringValues
(NuGet)
Dec 21, 2022
A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd)...
Low
Unreviewed
CVE-2020-10717
was published
May 24, 2022
NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource...
Low
Unreviewed
CVE-2020-5961
was published
May 24, 2022
JBossWS vulnerable to uncontrolled recursion
Low
CVE-2011-1483
was published
for
org.jboss.ws:jbossws-common
(Maven)
May 13, 2022
hutool-json vulnerable to memory exhaustion
Low
CVE-2022-45689
was published
for
cn.hutool:hutool-json
(Maven)
Dec 13, 2022
There is a resource management errors vulnerability in Huawei P30. Local attackers construct...
Low
Unreviewed
CVE-2020-9203
was published
May 24, 2022
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with...
Low
Unreviewed
CVE-2019-19922
was published
May 24, 2022
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a...
Low
Unreviewed
CVE-2001-0666
was published
Apr 30, 2022
Trend Micro Antivirus for Mac 2021 (Consumer) is vulnerable to a memory exhaustion vulnerability...
Low
Unreviewed
CVE-2021-25227
was published
May 24, 2022
Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a...
Low
Unreviewed
CVE-2002-1876
was published
Apr 30, 2022
Denial of service in fast-csv
Low
CVE-2020-26256
was published
for
@fast-csv/parse
(npm)
Dec 8, 2020
Regular Expression Denial of Service (REDoS) in httplib2
Low
CVE-2021-21240
was published
for
httplib2
(pip)
Feb 8, 2021
Regular Expression Denial of Service (ReDoS) in braces
Low
CVE-2018-1109
was published
for
braces
(npm)
Jan 6, 2022
Denial of service attack via push rule patterns in matrix-synapse
Low
CVE-2021-29471
was published
for
matrix-synapse
(pip)
May 13, 2021
ProTip!
Advisories are also available from the
GraphQL API