GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop...
High
Unreviewed
CVE-2017-7701
was published
May 13, 2022
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an...
High
Unreviewed
CVE-2017-7700
was published
May 13, 2022
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop,...
High
Unreviewed
CVE-2017-6467
was published
May 13, 2022
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop,...
High
Unreviewed
CVE-2017-6474
was published
May 13, 2022
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop,...
High
Unreviewed
CVE-2017-6472
was published
May 13, 2022
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by...
High
Unreviewed
CVE-2017-6470
was published
May 13, 2022
It was discovered that a programming error in the processing of HTTPS requests in the Apache...
High
Unreviewed
CVE-2017-6056
was published
May 13, 2022
This vulnerability allows any attacker to cause the PeerTube server to stop responding to...
High
Unreviewed
CVE-2025-32947
was published
Apr 15, 2025
SurrealDB CPU exhaustion via custom functions result in total DoS
High
GHSA-pxw4-94j3-v9pf
was published
for
surrealdb
(Rust)
Apr 11, 2025
HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote...
High
Unreviewed
CVE-2024-45506
was published
Sep 4, 2024
Improper Handling of Exceptional Conditions vulnerability in Daurnimator HTTP Library for Lua...
High
Unreviewed
CVE-2023-4540
was published
Sep 5, 2023
In Azle, calling `setTimer` causes infinite loop of timers
High
CVE-2025-29776
was published
for
azle
(npm)
Mar 14, 2025
A vulnerability has been identified in Nucleus 4 (All versions < V4.1.0), Nucleus NET (All...
High
Unreviewed
CVE-2021-25663
was published
May 24, 2022
A vulnerability has been identified in Nucleus 4 (All versions < V4.1.0), Nucleus NET (All...
High
Unreviewed
CVE-2021-25664
was published
May 24, 2022
phpseclib Infinite Loop vulnerability
High
CVE-2023-27560
was published
for
phpseclib/phpseclib
(Composer)
Mar 3, 2023
OpenDJ Denial of Service (DoS) using alias loop
High
CVE-2025-27497
was published
for
org.openidentityplatform.opendj:opendj-server-legacy
(Maven)
Mar 5, 2025
EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown...
High
Unreviewed
CVE-2023-45232
was published
Jan 16, 2024
EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option...
High
Unreviewed
CVE-2023-45233
was published
Jan 16, 2024
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input...
High
Unreviewed
CVE-2024-40675
was published
Jan 28, 2025
In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible...
High
Unreviewed
CVE-2017-13313
was published
Nov 16, 2024
Drupal core Denial of Service
High
CVE-2024-11941
was published
for
drupal/core
(Composer)
Dec 5, 2024
Uncontrolled resource consumption in validators Python package
High
CVE-2019-19588
was published
for
validators
(pip)
Jan 21, 2020
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of...
High
Unreviewed
CVE-2024-52532
was published
Nov 11, 2024
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to...
High
Unreviewed
CVE-2024-50319
was published
Nov 12, 2024
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to...
High
Unreviewed
CVE-2024-50321
was published
Nov 12, 2024
ProTip!
Advisories are also available from the
GraphQL API