GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,049
Maven
5,000+
npm
4,787
NuGet
825
pip
4,384
Pub
12
RubyGems
988
Rust
1,144
Swift
50
Unreviewed advisories
All unreviewed
5,000+
3,199 advisories
Filter by severity
pypdf: Manipulated RunLengthDecode streams can exhaust RAM
Moderate
CVE-2026-28351
was published
for
pypdf
(pip)
Feb 28, 2026
Snowflake JDBC Driver is Vulnerable to Uncontrolled Resource Consumption through SdkProxyRoutePlanner
Low
CVE-2026-3293
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Feb 27, 2026
apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
High
CVE-2026-25140
was published
for
chainguard-dev/apko
(Go)
Feb 4, 2026
Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
Moderate
CVE-2026-26047
was published
for
moodle/moodle
(Composer)
Feb 21, 2026
Undertow's url-encoded request path information can be broken on ajp-listener
High
CVE-2024-6162
was published
for
io.undertow:undertow-core
(Maven)
Jun 20, 2024
Eclipse Vert.x vulnerable to a memory leak in TCP servers
Moderate
CVE-2024-1300
was published
for
io.vertx:vertx-core
(Maven)
Apr 2, 2024
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Moderate
CVE-2026-27204
was published
for
wasmtime
(Rust)
Feb 24, 2026
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file...
High
Unreviewed
CVE-2023-52355
was published
Jan 25, 2024
Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial...
Moderate
Unreviewed
CVE-2026-26937
was published
Feb 26, 2026
pypdf: Manipulated FlateDecode XFA streams can exhaust RAM
Moderate
CVE-2026-27888
was published
for
pypdf
(pip)
Feb 26, 2026
TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the...
Critical
Unreviewed
CVE-2025-70327
was published
Feb 23, 2026
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted...
High
Unreviewed
CVE-2024-4467
was published
Jul 2, 2024
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin...
High
Unreviewed
CVE-2025-67445
was published
Feb 24, 2026
ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profile
Moderate
CVE-2026-26066
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Infinite loop vulnerability when parsing a PCD file
High
CVE-2026-24485
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick: Converting multi-layer nested MVG to SVG can cause DoS
Moderate
CVE-2026-24484
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ajv has ReDoS when using `$data` option
Moderate
CVE-2025-69873
was published
for
ajv
(npm)
Feb 11, 2026
OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs
Moderate
CVE-2026-27576
was published
for
openclaw
(npm)
Feb 20, 2026
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Moderate
CVE-2026-25122
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
Denial-of-service condition in M-Files Server versions before 25.11.15392.1 allows an...
High
Unreviewed
CVE-2025-11681
was published
Nov 17, 2025
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23...
Moderate
Unreviewed
CVE-2024-0563
was published
Feb 23, 2024
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 ...
High
Unreviewed
CVE-2024-4056
was published
Apr 26, 2024
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource...
Moderate
Unreviewed
CVE-2023-6910
was published
Dec 20, 2023
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4...
High
Unreviewed
CVE-2023-0384
was published
Apr 20, 2023
A vulnerability was determined in birkir prime up to 0.4.0.beta.0. This affects an unknown...
Moderate
Unreviewed
CVE-2026-1174
was published
Jan 19, 2026
ProTip!
Advisories are also available from the
GraphQL API