GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,794
Maven
5,000+
npm
4,402
NuGet
772
pip
4,179
Pub
12
RubyGems
965
Rust
1,075
Swift
45
Unreviewed advisories
All unreviewed
5,000+
276 advisories
Filter by severity
ImageMagick's failure to limit MVG mutual causes Stack Overflow
Moderate
CVE-2025-68950
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 30, 2025
ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack
Moderate
CVE-2025-68618
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 30, 2025
In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix infinite recursion...
High
Unreviewed
CVE-2024-35886
was published
May 19, 2024
In the Linux kernel, the following vulnerability has been resolved:
atm: clip: Fix infinite...
High
Unreviewed
CVE-2025-38459
was published
Jul 25, 2025
Nodemailer is vulnerable to DoS through Uncontrolled Recursion
Moderate
CVE-2025-14874
was published
for
nodemailer
(npm)
Dec 18, 2025
OpenSearch is vulnerable to DoS via complex query_string inputs
High
CVE-2025-9624
was published
for
org.opensearch:opensearch-common
(Maven)
Nov 25, 2025
uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by...
Low
Unreviewed
CVE-2025-67899
was published
Dec 15, 2025
In the Linux kernel, the following vulnerability has been resolved:
powercap: arm_scmi: Remove...
Moderate
Unreviewed
CVE-2023-53428
was published
Sep 18, 2025
In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm -...
Moderate
Unreviewed
CVE-2022-50407
was published
Sep 18, 2025
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive...
High
Unreviewed
CVE-2024-8176
was published
Mar 14, 2025
Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep...
High
Unreviewed
CVE-2016-4425
was published
May 17, 2022
MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via...
High
Unreviewed
CVE-2020-28196
was published
May 24, 2022
Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all...
High
Unreviewed
CVE-2025-59789
was published
Dec 1, 2025
node-forge has ASN.1 Unbounded Recursion
High
CVE-2025-66031
was published
for
node-forge
(npm)
Nov 26, 2025
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: KVM: Fix stack...
Moderate
Unreviewed
CVE-2025-39704
was published
Sep 5, 2025
IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain...
Moderate
Unreviewed
CVE-2025-36158
was published
Nov 21, 2025
In the Linux kernel, the following vulnerability has been resolved:
tracing/osnoise: Fix crash...
Moderate
Unreviewed
CVE-2025-38493
was published
Jul 28, 2025
In the Linux kernel, the following vulnerability has been resolved:
powerpc/perf: Optimize...
Moderate
Unreviewed
CVE-2022-50118
was published
Jun 18, 2025
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btintel: Check...
Moderate
Unreviewed
CVE-2025-38315
was published
Jul 10, 2025
In the Linux kernel, the following vulnerability has been resolved:
fbdev: omapfb: Add 'plane'...
Moderate
Unreviewed
CVE-2025-37851
was published
May 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
perf: Improve missing...
Moderate
Unreviewed
CVE-2022-49782
was published
May 1, 2025
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Moderate
CVE-2025-48924
was published
for
commons-lang:commons-lang
(Maven)
Jul 11, 2025
Uncontrolled Recursion in Loofah
High
CVE-2022-23516
was published
for
loofah
(RubyGems)
Dec 13, 2022
GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of...
High
Unreviewed
CVE-2024-0208
was published
Jan 3, 2024
DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or...
High
Unreviewed
CVE-2024-0211
was published
Jan 3, 2024
ProTip!
Advisories are also available from the
GraphQL API