GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
478 advisories
Filter by severity
msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker...
Moderate
Unreviewed
CVE-2026-90472
was published
Sep 12, 2026
A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used...
Moderate
Unreviewed
CVE-2026-88763
was published
Sep 10, 2026
An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go...
Moderate
Unreviewed
CVE-2026-19201
was published
Sep 9, 2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny...
High
Unreviewed
CVE-2026-69378
was published
Sep 8, 2026
XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that...
High
Unreviewed
CVE-2026-73321
was published
Sep 8, 2026
Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets deeply nested untrusted...
High
Unreviewed
CVE-2026-11573
was published
Sep 8, 2026
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-17440
was published
Sep 4, 2026
A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an...
Moderate
Unreviewed
CVE-2026-14255
was published
Sep 2, 2026
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
High
CVE-2026-76098
was published
for
mistune
(pip)
Sep 2, 2026
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
Moderate
CVE-2026-12876
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
Moderate
CVE-2026-81724
was published
for
nltk
(pip)
Sep 2, 2026
Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in...
High
Unreviewed
CVE-2026-81928
was published
Sep 2, 2026
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers...
High
Unreviewed
CVE-2026-52132
was published
Sep 1, 2026
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to...
High
Unreviewed
CVE-2026-52130
was published
Sep 1, 2026
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with...
Moderate
Unreviewed
CVE-2026-82797
was published
Aug 31, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
An attacker that has valid credentials can send crafted compressed data that causes the affected...
Moderate
Unreviewed
CVE-2026-73209
was published
Aug 28, 2026
Duplicate Advisory: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
Moderate
GHSA-pf76-q698-37v8
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
High
Unreviewed
CVE-2026-47851
was published
Aug 27, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled...
Moderate
Unreviewed
CVE-2026-16781
was published
Aug 24, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
High
CVE-2026-54623
was published
for
django-cms
(pip)
Aug 24, 2026
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
High
GHSA-892m-gcq8-2468
was published
for
justhtml
(pip)
Aug 23, 2026
•
withdrawn
Duplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
High
GHSA-cv2g-m8rr-888c
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
ProTip!
Advisories are also available from the
GraphQL API