Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

561 advisories

Loading
Allocation of Resources Without Limits or Throttling in HashiCorp Nomad High
CVE-2020-7218 was published for github.com/hashicorp/nomad (Go) May 18, 2021
Denial of Service (DoS) in HashiCorp Consul High
CVE-2020-7219 was published for github.com/hashicorp/consul (Go) May 18, 2021
Puma's Keepalive Connections Causing Denial Of Service High
CVE-2021-29509 was published for puma (RubyGems) May 18, 2021
MSP-Greg wjordan
ioquatix
Credited to MSP-Greg, wjordan, and ioquatix
Authorization service vulnerable to DDos attacks in Apache CFX High
CVE-2021-22696 was published for org.apache.cxf:apache-cxf (Maven) May 13, 2021
Arbitrary Code Execution in json-ptr High
CVE-2020-7766 was published for json-ptr (npm) May 10, 2021
tdunlap607
Credited to tdunlap607
Regular expression denial of service in npm-user-validate High
CVE-2020-7754 was published for npm-user-validate (npm) May 10, 2021
Regular Expression Denial of Service in dat.gui High
CVE-2020-7755 was published for dat.gui (npm) May 10, 2021
Regular Expression Denial of Service in trim High
CVE-2020-7753 was published for trim (npm) May 10, 2021
Uncontrolled Resource Consumption in json-bigint High
CVE-2020-8237 was published for json-bigint (npm) May 7, 2021
Regular Expression Denial of Service in ua-parser-js High
CVE-2020-7733 was published for ua-parser-js (npm) May 7, 2021
Regular Expression Denial of Service (ReDoS) in ua-parser-js High
CVE-2021-27292 was published for ua-parser-js (npm) May 6, 2021
Denial of service in chrono-node High
CVE-2021-23371 was published for chrono-node (npm) May 6, 2021
Possible DoS Vulnerability in Action Controller Token Authentication High
CVE-2021-22904 was published for actionpack (RubyGems) May 5, 2021
Denial of Service in Action Dispatch High
CVE-2021-22902 was published for actionpack (RubyGems) May 5, 2021
Regular expression Denial of Service (ReDoS) in EmailValidator class in V7 compatibility module in Vaadin 8 High
CVE-2021-31409 was published for com.vaadin:vaadin-compatibility-server (Maven) May 4, 2021
StefanPenndorf
Credited to StefanPenndorf
Uncontrolled Resource Consumption in urllib3 High
CVE-2020-7212 was published for urllib3 (pip) Apr 30, 2021
Node-Redis potential exponential regex in monitor mode High
CVE-2021-29469 was published for redis (npm) Apr 27, 2021
erik-krogh
Credited to erik-krogh
py vulnerable to Regular Expression Denial of Service High
CVE-2020-29651 was published for py (pip) Apr 20, 2021
Sydent vulnerable to denial of service attack via memory exhaustion High
CVE-2021-29430 was published for matrix-sydent (pip) Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17 High
GHSA-crh4-294p-vcfq was published for com.vaadin:vaadin-text-field-flow (Maven) Apr 19, 2021
Regular expression denial of service (ReDoS) in EmailValidator class in Vaadin 7 High
CVE-2020-36320 was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
SunBK201
Credited to SunBK201
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17 High
CVE-2021-31405 was published for com.vaadin:vaadin-bom (Maven) Apr 19, 2021
Denial of Service (DoS) via the unsetByPath function in jsjoints High
CVE-2020-28479 was published for jointjs (npm) Apr 13, 2021
Prototype Pollution in decal High
CVE-2020-28450 was published for decal (npm) Apr 13, 2021
Prototype Pollution in decal High
CVE-2020-28449 was published for decal (npm) Apr 13, 2021
ProTip! Advisories are also available from the GraphQL API