GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,623
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
22 advisories
Filter by severity
PyPDF2 quadratic runtime with malformed PDF missing xref marker
Moderate
CVE-2023-36810
was published
for
PyPDF2
(pip)
Jun 30, 2023
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Low
CVE-2025-55304
was published
for
Exiv2
(pip)
Aug 29, 2025
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
High
CVE-2025-62727
was published
for
starlette
(pip)
Oct 28, 2025
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
High
CVE-2025-64458
was published
for
django
(pip)
Nov 5, 2025
Django is vulnerable to DoS via XML serializer text extraction
Moderate
CVE-2025-64460
was published
for
Django
(pip)
Dec 2, 2025
Django has Inefficient Algorithmic Complexity
Low
CVE-2025-14550
was published
for
Django
(pip)
Feb 3, 2026
Django has Inefficient Algorithmic Complexity
Low
CVE-2026-1285
was published
for
Django
(pip)
Feb 3, 2026
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
Moderate
CVE-2026-28804
was published
for
pypdf
(pip)
Mar 2, 2026
pypdf has inefficient decoding of array-based streams
Moderate
CVE-2026-33123
was published
for
pypdf
(pip)
Mar 18, 2026
Django has potential DoS via MultiPartParser through crafted multipart uploads
Moderate
CVE-2026-33033
was published
for
Django
(pip)
Apr 7, 2026
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
High
CVE-2026-42304
was published
for
Twisted
(pip)
May 5, 2026
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
High
CVE-2026-53539
was published
for
python-multipart
(pip)
Jun 15, 2026
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
Moderate
CVE-2026-49460
was published
for
pypdf
(pip)
Jun 16, 2026
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
Moderate
CVE-2026-55206
was published
for
py7zr
(pip)
Jun 19, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
sqlparse: Quadratic O(n²) DoS in group_comments
High
CVE-2026-71491
was published
for
sqlparse
(pip)
Aug 17, 2026
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
High
CVE-2026-54284
was published
for
sqlparse
(pip)
Aug 17, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API