GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
947 advisories
Filter by severity
Scrapy with Brotli is vulnerable to a denial of service (DoS) attack due to decompression
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
gnark-crypto allows unchecked memory allocation during vector deserialization
High
GHSA-fj2x-735w-74vq
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 30, 2025
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
High
CVE-2025-62727
was published
for
starlette
(pip)
Oct 28, 2025
Liferay Portal Vulnerable to DoS via Crafted Headless API Request
High
CVE-2025-62260
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Keycloak TLS Client-Initiated Renegotiation Denial of Service
High
CVE-2025-11419
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Oct 27, 2025
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
Moderate
CVE-2025-12194
was published
for
org.bouncycastle:bc-fips
(Maven)
Oct 25, 2025
ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
Moderate
CVE-2025-60790
was published
for
processwire/processwire
(Composer)
Oct 21, 2025
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
High
CVE-2025-59043
was published
for
github.com/openbao/openbao
(Go)
Oct 17, 2025
Parallax is vulnerable to DoS via malicious p2p message
High
GHSA-xc79-566c-j4qx
was published
for
github.com/microstack-tech/parallax
(Go)
Oct 10, 2025
Authlib : JWE zip=DEF decompression bomb enables DoS
Moderate
CVE-2025-62706
was published
for
authlib
(pip)
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
CVE-2025-61921
was published
for
sinatra
(RubyGems)
Oct 10, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
High
CVE-2025-61919
was published
for
rack
(RubyGems)
Oct 10, 2025
Amazon.IonDotnet is vulnerable to Denial of Service attacks
High
CVE-2025-11573
was published
for
Amazon.IonDotnet
(NuGet)
Oct 9, 2025
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Moderate
CVE-2025-61620
was published
for
vllm
(pip)
Oct 7, 2025
Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
High
CVE-2025-61772
was published
for
rack
(RubyGems)
Oct 7, 2025
Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
High
CVE-2025-61771
was published
for
rack
(RubyGems)
Oct 7, 2025
Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
High
CVE-2025-61770
was published
for
rack
(RubyGems)
Oct 7, 2025
github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
High
CVE-2025-61595
was published
for
github.com/MANTRA-Chain/mantrachain
(Go)
Sep 30, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
Finance.js vulnerable to DoS via the seekZero() parameter
High
CVE-2025-56572
was published
for
financejs
(npm)
Sep 30, 2025
@nubosoftware/node-static failure to catch exception can result in server crash
High
CVE-2025-11149
was published
for
@nubosoftware/node-static
(npm)
Sep 30, 2025
Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
High
CVE-2025-59830
was published
for
rack
(RubyGems)
Sep 25, 2025
apidoc-core is vulnerable to prototype pollution
High
CVE-2025-57317
was published
for
apidoc-core
(npm)
Sep 25, 2025
Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
Moderate
CVE-2025-6921
was published
for
transformers
(pip)
Sep 23, 2025
ProTip!
Advisories are also available from the
GraphQL API