GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
617 advisories
Filter by severity
pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character
Moderate
CVE-2023-36464
was published
for
PyPDF2
(pip)
Jun 30, 2023
OpenFGA Vulnerable to DoS from circular relationship definitions
Moderate
CVE-2023-43645
was published
for
github.com/openfga/openfga
(Go)
Sep 28, 2023
Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300...
High
Unreviewed
CVE-2023-1718
was published
Nov 1, 2023
Invalid handling of `X509_verify_cert()` internal errors in libssl
High
CVE-2021-4044
was published
for
openssl-src
(Rust)
Dec 15, 2021
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply...
High
Unreviewed
CVE-2022-23098
was published
Feb 10, 2022
asyncua vulnerable to denial of service via infinite loop
High
CVE-2023-26151
was published
for
asyncua
(pip)
Oct 3, 2023
A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications...
Moderate
Unreviewed
CVE-2023-20116
was published
Jun 28, 2023
A vulnerability, which was classified as problematic, was found in InternalError503 Forget It up...
Low
Unreviewed
CVE-2015-10103
was published
Apr 17, 2023
OpenFGA vulnerable to denial of service due to circular relationship
Moderate
CVE-2023-35933
was published
for
github.com/openfga/openfga
(Go)
Jun 28, 2023
PyPDF2 vulnerable to possible Infinite Loop when reading malformed objects
Moderate
CVE-2023-36807
was published
for
PyPDF2
(pip)
Jun 30, 2023
Loop with Unreachable Exit Condition in Netty
High
CVE-2016-4970
was published
for
io.netty:netty-handler
(Maven)
May 13, 2022
Istio vulnerable to denial of service
High
CVE-2019-18817
was published
for
istio.io/istio
(Go)
May 24, 2022
Denial of Service in Apache Commons Compress
High
CVE-2019-12402
was published
for
io.github.1tchy.java9modular.org.apache.commons:commons-compress
(Maven)
Oct 11, 2019
A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the...
High
Unreviewed
CVE-2022-46285
was published
Feb 7, 2023
Infinite certificate chain depth results in OctoRPKI running forever
Moderate
CVE-2021-3908
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser
Moderate
CVE-2018-17197
was published
for
org.apache.tika:tika-parsers
(Maven)
Dec 26, 2018
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process...
Low
Unreviewed
CVE-2015-6815
was published
May 24, 2022
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or...
Moderate
Unreviewed
CVE-2019-18180
was published
May 24, 2022
Pion DTLS Header reconstruction method can be thrown into an infinite loop
High
CVE-2022-29190
was published
for
github.com/pion/dtls
(Go)
May 24, 2022
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote...
Moderate
Unreviewed
CVE-2004-0753
was published
Apr 29, 2022
StackStorm st2 Infinite Loop Condition
High
CVE-2021-28667
was published
for
st2client
(pip)
May 24, 2022
•
withdrawn
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively...
Moderate
Unreviewed
CVE-2022-31628
was published
Sep 29, 2022
Routinator infinite loop vulnerability
High
CVE-2021-43172
was published
for
routinator
(Rust)
May 24, 2022
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of...
Moderate
Unreviewed
CVE-2021-3468
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API