GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
167 advisories
Filter by severity
AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection
High
CVE-2026-25762
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
High
CVE-2026-24133
was published
for
jspdf
(npm)
Feb 2, 2026
React Server Components have multiple Denial of Service Vulnerabilities
High
CVE-2026-23864
was published
for
react-server-dom-parcel
(npm)
Jan 29, 2026
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
High
GHSA-h25m-26qc-wcjf
was published
for
next
(npm)
Jan 28, 2026
SvelteKit is vulnerable to denial of service and possible SSRF when using prerendering
High
CVE-2025-67647
was published
for
@sveltejs/adapter-node
(npm)
Jan 15, 2026
Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
High
GHSA-5j59-xgg2-r9c4
was published
for
next
(npm)
Dec 12, 2025
Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
High
CVE-2025-68272
was published
for
signalk-server
(npm)
Jan 2, 2026
libxmljs has segmentation fault, potentially leading to a denial-of-service (DoS)
High
CVE-2025-25341
was published
for
libxmljs
(npm)
Dec 26, 2025
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
High
GHSA-x732-6j76-qmhm
was published
for
better-auth
(npm)
Dec 16, 2025
Vite Plugin React has a Denial of Service Vulnerability in React Server Components
High
GHSA-cpqf-f22c-r95x
was published
for
@vitejs/plugin-rsc
(npm)
Dec 12, 2025
Denial of Service Vulnerability in React Server Components
High
CVE-2025-67779
was published
for
react-server-dom-parcel
(npm)
Dec 12, 2025
Next Vulnerable to Denial of Service with Server Components
High
GHSA-mwv6-3258-q52c
was published
for
next
(npm)
Dec 11, 2025
Denial of Service Vulnerability in React Server Components
High
CVE-2025-55184
was published
for
react-server-dom-parcel
(npm)
Dec 11, 2025
loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
High
CVE-2022-37599
was published
for
loader-utils
(npm)
Oct 12, 2022
Moment.js vulnerable to Inefficient Regular Expression Complexity
High
CVE-2022-31129
was published
for
Moment.js
(npm)
Jul 6, 2022
ReDoS Vulnerability in ua-parser-js version
High
CVE-2022-25927
was published
for
ua-parser-js
(npm)
Jan 24, 2023
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
@nubosoftware/node-static failure to catch exception can result in server crash
High
CVE-2025-11149
was published
for
@nubosoftware/node-static
(npm)
Sep 30, 2025
Finance.js vulnerable to DoS via the seekZero() parameter
High
CVE-2025-56572
was published
for
financejs
(npm)
Sep 30, 2025
apidoc-core is vulnerable to prototype pollution
High
CVE-2025-57317
was published
for
apidoc-core
(npm)
Sep 25, 2025
Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity
High
CVE-2025-58451
was published
for
cattown
(npm)
Sep 9, 2025
@stryker-mutator/util vulnerable to Prototype Pollution
High
CVE-2024-57085
was published
for
@stryker-mutator/util
(npm)
Feb 6, 2025
kangax html-minifier REDoS vulnerability
High
CVE-2022-37620
was published
for
html-minifier
(npm)
Oct 31, 2022
ProTip!
Advisories are also available from the
GraphQL API