GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
947 advisories
Filter by severity
Uncontrolled Resource Consumption in Apache Tika
Moderate
CVE-2020-1950
was published
for
org.apache.tika:tika
(Maven)
May 7, 2021
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Moderate
CVE-2021-21419
was published
for
eventlet
(pip)
May 7, 2021
Uncontrolled Resource Consumption in fastify-multipart
Moderate
CVE-2020-8136
was published
for
fastify-multipart
(npm)
May 6, 2021
Regular Expression Denial of Service (ReDoS) in ua-parser-js
High
CVE-2021-27292
was published
for
ua-parser-js
(npm)
May 6, 2021
Regular Expression Denial of Service in hosted-git-info
Moderate
CVE-2021-23362
was published
for
hosted-git-info
(npm)
May 6, 2021
Denial of service in chrono-node
High
CVE-2021-23371
was published
for
chrono-node
(npm)
May 6, 2021
Possible DoS Vulnerability in Action Controller Token Authentication
High
CVE-2021-22904
was published
for
actionpack
(RubyGems)
May 5, 2021
Denial of Service in Action Dispatch
High
CVE-2021-22902
was published
for
actionpack
(RubyGems)
May 5, 2021
Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8
High
CVE-2021-31409
was published
for
com.vaadin:vaadin-compatibility-server
(Maven)
May 4, 2021
Uncontrolled Resource Consumption in urllib3
High
CVE-2020-7212
was published
for
urllib3
(pip)
Apr 30, 2021
Node-Redis potential exponential regex in monitor mode
High
CVE-2021-29469
was published
for
redis
(npm)
Apr 27, 2021
Uncontrolled Resource Consumption in pillow
Moderate
GHSA-jgpv-4h4c-xhw3
was published
for
pillow
(pip)
Apr 23, 2021
py vulnerable to Regular Expression Denial of Service
High
CVE-2020-29651
was published
for
py
(pip)
Apr 20, 2021
Sydent vulnerable to denial of service attack via memory exhaustion
High
CVE-2021-29430
was published
for
matrix-sydent
(pip)
Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
High
GHSA-crh4-294p-vcfq
was published
for
com.vaadin:vaadin-text-field-flow
(Maven)
Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailValidator class in Vaadin 7
High
CVE-2020-36320
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
High
CVE-2021-31405
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 19, 2021
Sydent DoS (via resource exhaustion) due to improper input validation
Moderate
CVE-2021-29433
was published
for
matrix-sydent
(pip)
Apr 16, 2021
Denial of Service (DoS) via the unsetByPath function in jsjoints
High
CVE-2020-28479
was published
for
jointjs
(npm)
Apr 13, 2021
Prototype Pollution in asciitable.js
Critical
CVE-2020-7771
was published
for
asciitable.js
(npm)
Apr 13, 2021
Uncontrolled Resource Consumption in rdf-graph-array
Moderate
CVE-2019-10798
was published
for
rdf-graph-array
(npm)
Apr 13, 2021
Regular Expression Denial of Service (ReDoS) in es6-crawler-detect
Moderate
CVE-2020-28501
was published
for
es6-crawler-detect
(npm)
Apr 13, 2021
Denial of Service in get-ip-range
High
CVE-2021-27191
was published
for
get-ip-range
(npm)
Apr 13, 2021
ProTip!
Advisories are also available from the
GraphQL API