Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

625 advisories

Loading
Denial of service via malicious preflight requests in github.com/rs/cors Moderate
CVE-2025-47908 was published for github.com/rs/cors (Go) Jul 5, 2024
CrateDB has a Client initialized Session-Renegotiation DoS Moderate
CVE-2024-37309 was published for io.crate:crate (Maven) Jun 13, 2024
BaurzhanSakhariev
Credited to BaurzhanSakhariev
gqlparser denial of service vulnerability via the parserDirectives function Moderate
CVE-2023-49559 was published for github.com/vektah/gqlparser (Go) Jun 12, 2024
TYPO3 Denial of Service in Online Media Asset Handling Moderate
GHSA-f3wf-q4fj-3gxf was published for typo3/cms (Composer) Jun 7, 2024
is_closing_session() allows users to consume RAM in the Apport process Moderate Unreviewed
CVE-2022-28656 was published Jun 5, 2024
is_closing_session() allows users to fill up apport.log Moderate Unreviewed
CVE-2022-28654 was published Jun 5, 2024
TYPO3 Denial of Service in Online Media Asset Handling Moderate
GHSA-29m4-mx89-3mjg was published for typo3/cms-core (Composer) May 30, 2024
Denial of service of Minder Server from maliciously crafted GitHub attestations Moderate
CVE-2024-35238 was published for github.com/stacklok/minder (Go) May 28, 2024
AdamKorcz DavidKorczynski
Credited to AdamKorcz and DavidKorczynski
OpenLiteSpeed before 1.8.1 mishandles chunked encoding. Moderate Unreviewed
CVE-2024-31617 was published May 22, 2024
ProTip! Advisories are also available from the GraphQL API