GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
23 advisories
Filter by severity
vm2 before 3.6.11 vulnerable to sandbox escape
High
CVE-2019-10761
was published
for
vm2
(npm)
Jul 14, 2022
msgpackr's conversion of property names to strings can trigger infinite recursion
High
CVE-2023-52079
was published
for
msgpackr
(npm)
Dec 28, 2023
Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries
High
CVE-2024-43414
was published
for
@apollo/gateway
(npm)
Aug 27, 2024
node-forge has ASN.1 Unbounded Recursion
High
CVE-2025-66031
was published
for
node-forge
(npm)
Nov 26, 2025
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack
High
CVE-2026-27601
was published
for
underscore
(npm)
Mar 3, 2026
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
High
CVE-2026-3520
was published
for
multer
(npm)
Mar 5, 2026
flatted vulnerable to unbounded recursion DoS in parse() revive phase
High
CVE-2026-32141
was published
for
flatted
(npm)
Mar 13, 2026
Parse Server crash via deeply nested query condition operators
High
CVE-2026-32944
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server has a query condition depth bypass via pre-validation transform pipeline
High
CVE-2026-33498
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server LiveQuery subscription query depth bypass
High
CVE-2026-33508
was published
for
parse-server
(npm)
Mar 20, 2026
@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags
High
GHSA-5jg4-p4qw-cgfr
was published
for
@stablelib/cbor
(npm)
Apr 4, 2026
Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)
High
CVE-2026-40879
was published
for
@nestjs/microservices
(npm)
Apr 14, 2026
xmldom: Uncontrolled recursion in XML serialization leads to DoS
High
CVE-2026-41673
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
liquidjs has a Denial of Service via circular block reference in layout
High
CVE-2026-41311
was published
for
liquidjs
(npm)
Apr 24, 2026
Apache Thrift Node.js bindings vulnerable to Uncontrolled Recursion
High
CVE-2026-41636
was published
for
thrift
(npm)
Apr 28, 2026
Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
High
CVE-2026-41680
was published
for
marked
(npm)
Apr 29, 2026
protobuf.js: Denial of service through unbounded protobuf recursion
High
CVE-2026-44289
was published
for
protobufjs
(npm)
May 12, 2026
protobufjs: Denial of service through unbounded Any expansion during JSON conversion
High
CVE-2026-48712
was published
for
protobufjs
(npm)
Jun 15, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
High
CVE-2026-73566
was published
for
tar
(npm)
Jul 24, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs
High
CVE-2026-40345
was published
for
deepmerge-ts
(npm)
Aug 17, 2026
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
ProTip!
Advisories are also available from the
GraphQL API