GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
This vulnerability allows remote attackers to create a denial-of-service condition on affected...
High
Unreviewed
CVE-2022-37013
was published
Mar 29, 2023
libxml as used in Nokogiri has an infinite loop in a certain end-of-file situation
High
CVE-2020-7595
was published
for
nokogiri
(RubyGems)
Feb 24, 2020
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
High
CVE-2017-16932
was published
for
nokogiri
(RubyGems)
May 13, 2022
Integer Overflow/Infinite Loop in the http crate
High
CVE-2020-25574
was published
for
http
(Rust)
Aug 25, 2021
SwiftNIO Extras vulnerable to improper detection of complete HTTP body decompression
High
CVE-2022-3252
was published
for
github.com/apple/swift-nio-extras
(Swift)
Jun 7, 2023
A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some...
High
Unreviewed
CVE-2022-44617
was published
Feb 7, 2023
Routinator infinite loop vulnerability
High
CVE-2021-43172
was published
for
routinator
(Rust)
May 24, 2022
StackStorm st2 Infinite Loop Condition
High
CVE-2021-28667
was published
for
st2client
(pip)
May 24, 2022
•
withdrawn
Pion DTLS Header reconstruction method can be thrown into an infinite loop
High
CVE-2022-29190
was published
for
github.com/pion/dtls
(Go)
May 24, 2022
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the...
High
Unreviewed
CVE-2022-46285
was published
Feb 7, 2023
Denial of Service in Apache Commons Compress
High
CVE-2019-12402
was published
for
io.github.1tchy.java9modular.org.apache.commons:commons-compress
(Maven)
Oct 11, 2019
Istio vulnerable to denial of service
High
CVE-2019-18817
was published
for
istio.io/istio
(Go)
May 24, 2022
Loop with Unreachable Exit Condition in Netty
High
CVE-2016-4970
was published
for
io.netty:netty-handler
(Maven)
May 13, 2022
asyncua vulnerable to denial of service via infinite loop
High
CVE-2023-26151
was published
for
asyncua
(pip)
Oct 3, 2023
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply...
High
Unreviewed
CVE-2022-23098
was published
Feb 10, 2022
Invalid handling of `X509_verify_cert()` internal errors in libssl
High
CVE-2021-4044
was published
for
openssl-src
(Rust)
Dec 15, 2021
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300...
High
Unreviewed
CVE-2023-1718
was published
Nov 1, 2023
FaucetSDN Ryu Denial of Service Vulnerability
High
CVE-2020-35139
was published
for
ryu
(pip)
Aug 11, 2023
FaucetSDN Ryu Denial of Service Vulnerability
High
CVE-2020-35141
was published
for
ryu
(pip)
Aug 11, 2023
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc...
High
Unreviewed
CVE-2023-40458
was published
Nov 30, 2023
Candid infinite decoding loop through specially crafted payload
High
CVE-2023-6245
was published
for
candid
(Rust)
Dec 8, 2023
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of...
High
Unreviewed
CVE-2023-50981
was published
Dec 27, 2023
hutool-core discovered to contain an infinite loop in the StrSplitter.splitByRegex function
High
CVE-2023-51075
was published
for
cn.hutool:hutool-core
(Maven)
Dec 27, 2023
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via...
High
Unreviewed
CVE-2021-42260
was published
May 24, 2022
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that...
High
Unreviewed
CVE-2023-43511
was published
Jan 2, 2024
ProTip!
Advisories are also available from the
GraphQL API