GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,316 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
RDMA/hns: Fix cpu stuck...
Moderate
Unreviewed
CVE-2024-56722
was published
Dec 29, 2024
In the Linux kernel, the following vulnerability has been resolved:
io_uring/tctx: work around...
Moderate
Unreviewed
CVE-2024-56584
was published
Dec 27, 2024
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows...
Moderate
Unreviewed
CVE-2023-1544
was published
Mar 23, 2023
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2024-38286
was published
for
org.apache.tomcat:tomcat-util
(Maven)
Nov 7, 2024
In the Linux kernel, the following vulnerability has been resolved:
arm64/sme: Always exit...
Moderate
Unreviewed
CVE-2024-26618
was published
Mar 11, 2024
An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific...
Moderate
Unreviewed
CVE-2025-41704
was published
Oct 14, 2025
Authlib : JWE zip=DEF decompression bomb enables DoS
Moderate
CVE-2025-62706
was published
for
authlib
(pip)
Oct 10, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
NeuVector telemetry sender is vulnerable to MITM and DoS
High
CVE-2025-54470
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
Searching Opencast may cause a denial of service
Moderate
CVE-2024-52797
was published
for
org.opencastproject:opencast-elasticsearch-impl
(Maven)
Nov 20, 2024
otelgrpc DoS vulnerability due to unbound cardinality metrics
High
CVE-2023-47108
was published
for
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
(Go)
Nov 12, 2023
Keycloak TLS Client-Initiated Renegotiation Denial of Service
High
CVE-2025-11419
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Oct 27, 2025
An attacker that gains SSH access to an unprivileged account may be able to disrupt services ...
Moderate
Unreviewed
CVE-2025-59459
was published
Oct 27, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18...
High
Unreviewed
CVE-2025-11447
was published
Oct 27, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18...
Moderate
Unreviewed
CVE-2025-11974
was published
Oct 27, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5,...
High
Unreviewed
CVE-2025-10497
was published
Oct 27, 2025
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size...
High
Unreviewed
CVE-2023-5379
was published
Dec 13, 2023
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
High
CVE-2025-12044
was published
for
github.com/hashicorp/vault
(Go)
Oct 23, 2025
github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
High
CVE-2025-61595
was published
for
github.com/MANTRA-Chain/mantrachain
(Go)
Sep 30, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Moderate
Unreviewed
CVE-2025-53069
was published
Oct 21, 2025
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Moderate
CVE-2025-61620
was published
for
vllm
(pip)
Oct 7, 2025
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of...
High
Unreviewed
CVE-2020-3569
was published
May 24, 2022
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR...
High
Unreviewed
CVE-2020-3566
was published
May 24, 2022
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows...
High
Unreviewed
CVE-2025-56223
was published
Oct 20, 2025
rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or...
Moderate
Unreviewed
CVE-2025-62672
was published
Oct 19, 2025
ProTip!
Advisories are also available from the
GraphQL API