GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,883
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,200
NuGet
743
pip
3,977
Pub
12
RubyGems
947
Rust
1,032
Swift
39
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
REXML has DoS condition when parsing malformed XML file
Low
CVE-2025-58767
was published
for
rexml
(RubyGems)
Sep 17, 2025
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The...
Low
Unreviewed
CVE-2025-40802
was published
Sep 9, 2025
Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
Low
CVE-2025-9092
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 16, 2025
Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for...
Low
Unreviewed
CVE-2025-27576
was published
Aug 12, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported...
Low
Unreviewed
CVE-2025-50104
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Low
Unreviewed
CVE-2025-50098
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). ...
Low
Unreviewed
CVE-2025-50100
was published
Jul 15, 2025
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component:...
Low
Unreviewed
CVE-2025-30752
was published
Jul 15, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
brace-expansion Regular Expression Denial of Service vulnerability
Low
CVE-2025-5889
was published
for
brace-expansion
(npm)
Jun 9, 2025
Ackites KillWxapkg Zip Bomb Resource Exhaustion
Low
CVE-2025-5031
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
Uncontrolled resource consumption for some Edge Orchestrator software for Intel(R) Tiber™ Edge...
Low
Unreviewed
CVE-2025-20616
was published
May 13, 2025
Apache Commons Configuration Uncontrolled Resource Consumption
Low
CVE-2025-46392
was published
for
commons-configuration:commons-configuration
(Maven)
May 9, 2025
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as...
Low
Unreviewed
CVE-2025-4215
was published
May 2, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). ...
Low
Unreviewed
CVE-2025-30681
was published
Apr 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Low
Unreviewed
CVE-2024-21232
was published
Oct 15, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). ...
Low
Unreviewed
CVE-2024-21231
was published
Oct 15, 2024
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Low
CVE-2024-6762
was published
for
org.eclipse.jetty:jetty-servlets
(Maven)
Oct 14, 2024
A denial-of-service vulnerability could allow an authenticated user to trigger an internal...
Low
Unreviewed
CVE-2022-4003
was published
Jul 31, 2024
A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled...
Low
Unreviewed
CVE-2024-6501
was published
Jul 9, 2024
A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any...
Low
Unreviewed
CVE-2024-6126
was published
Jul 3, 2024
DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior...
Low
Unreviewed
CVE-2024-5469
was published
Jun 14, 2024
octo-sts vulnerable to unauthenticated attacker causing unbounded CPU and memory usage
Low
CVE-2024-34079
was published
for
github.com/octo-sts/app
(Go)
May 13, 2024
Mattermost fails to limit the size of a request path
Low
CVE-2024-22091
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial...
Low
Unreviewed
CVE-2024-3872
was published
Apr 16, 2024
ProTip!
Advisories are also available from the
GraphQL API