GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,721
Erlang
35
GitHub Actions
29
Go
2,306
Maven
5,000+
npm
3,946
NuGet
711
pip
3,723
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
332 advisories
Filter by severity
Meteor Affected By Inefficient Regular Expression Complexity
Moderate
CVE-2025-4727
was published
for
meteor
(npm)
May 16, 2025
Linkerd resource exhaustion vulnerability
Moderate
CVE-2025-43915
was published
for
github.com/linkerd/linkerd2
(Go)
May 5, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
Apereo CAS has inefficient regular expression complexity
Moderate
CVE-2025-3986
was published
for
org.apereo.cas:cas-server-core-configuration-metadata-repository
(Maven)
Apr 27, 2025
GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-733v-p3h5-qpq7
was published
for
@escape.tech/graphql-armor-cost-limit
(npm)
Apr 25, 2025
Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
Moderate
CVE-2024-52981
was published
for
org.elasticsearch:elasticsearch
(Maven)
Apr 8, 2025
Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Moderate
CVE-2024-52980
was published
for
org.elasticsearch:elasticsearch
(Maven)
Apr 8, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2025-0453
was published
for
mlflow
(pip)
Mar 20, 2025
MLflow Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-6838
was published
for
mlflow
(pip)
Mar 20, 2025
LlamaIndex Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-12910
was published
for
llama-index
(pip)
Mar 20, 2025
OpenShift Hive Has an Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2024-25132
was published
for
github.com/openshift/hive
(Go)
Mar 19, 2025
CGI has Denial of Service (DoS) potential in Cookie.parse
Moderate
CVE-2025-27219
was published
for
cgi
(RubyGems)
Mar 3, 2025
DoS in go-jose Parsing
Moderate
CVE-2025-27144
was published
for
github.com/go-jose/go-jose
(Go)
Feb 24, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory
Moderate
CVE-2025-27100
was published
for
github.com/treeverse/lakefs
(Go)
Feb 21, 2025
Node Denial of Service via kubelet Checkpoint API
Moderate
CVE-2025-0426
was published
for
k8s.io/kubernetes
(Go)
Feb 13, 2025
Denial of Service attack on windows app using Netty
Moderate
CVE-2025-25193
was published
for
io.netty:netty-common
(Maven)
Feb 10, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
Apache Wicket: An attacker can intentionally trigger a memory leak
Moderate
CVE-2024-53299
was published
for
org.apache.wicket:wicket-core
(Maven)
Jan 23, 2025
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
Moderate
CVE-2024-10846
was published
for
github.com/compose-spec/compose-go/v2
(Go)
Jan 21, 2025
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-54677
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Dec 17, 2024
Withdrawn Advisory: Netty vulnerability included in redis lettuce
Moderate
GHSA-q4h9-7rxj-7gx2
was published
for
io.lettuce:lettuce-core
(Maven)
Dec 2, 2024
•
withdrawn
Spring MVC controller vulnerable to a DoS attack
Moderate
CVE-2024-38828
was published
for
org.springframework:spring-webmvc
(Maven)
Nov 18, 2024
Denial of Service attack on windows app using netty
Moderate
CVE-2024-47535
was published
for
io.netty:netty-common
(Maven)
Nov 12, 2024
wasm3 uncontrolled memory allocation vulnerability
Moderate
CVE-2024-27529
was published
for
github.com/shareup/wasm-interpreter-apple
(pip)
Nov 9, 2024
Undertow Denial of Service vulnerability
Moderate
CVE-2023-1973
was published
for
io.undertow:undertow-core
(Maven)
Nov 7, 2024
ProTip!
Advisories are also available from the
GraphQL API