GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,618
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,042
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            257 advisories
        Filter by severity
        
      
      
    
                    
                      In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11896
                      
                      was published
                      Oct 17, 2025 
                    
                  
                    
                      When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54858
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-33096
                      
                      was published
                      Oct 12, 2025 
                    
                  
                    
                      When the module renders a Svg file that contains a <pattern> element, it might end up rendering...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10728
                      
                      was published
                      Oct 3, 2025 
                    
                  
                    
                      Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43718
                      
                      was published
                      Oct 1, 2025 
                    
                  
                    
                      express-xss-sanitizer has an unbounded recursion depth
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59364
                      
                      was published
                        for
                        
                          express-xss-sanitizer
                        
                        (npm)
                      Sep 26, 2025 
                    
                  
                    
                      Duplicate Advisory: express-xss-sanitizer has an unbounded recursion depth
                    
                      
  Moderate
                    
                
                      
                        GHSA-qhwp-454g-2gv4
                      
                      was published
                        for
                        
                          express-xss-sanitizer
                        
                        (npm)
                      Sep 15, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9714
                      
                      was published
                      Sep 10, 2025 
                    
                  
                    
                      LlamaIndex affected by a Denial of Service (DOS) in JSONReader
                    
                      
  High
                    
                
                      
                        CVE-2025-5302
                      
                      was published
                        for
                        
                          llama-index-core
                        
                        (pip)
                      Aug 26, 2025 
                    
                  
                    
                      XGrammar affected by Denial of Service by infinite recursion grammars
                    
                      
  High
                    
                
                      
                        CVE-2025-57809
                      
                      was published
                        for
                        
                          xgrammar
                        
                        (pip)
                      Aug 25, 2025 
                    
                  
                    
                      Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-24302
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20025
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-23325
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46206
                      
                      was published
                      Aug 4, 2025 
                    
                  
                    
                      An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50420
                      
                      was published
                      Aug 4, 2025 
                    
                  
                    
                      Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
                    
                      
  Low
                    
                
                      
                        GHSA-j87p-gjr6-m4pv
                      
                      was published
                        for
                        
                          serde-json-wasm
                        
                        (Rust)
                      Jul 27, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48924
                      
                      was published
                        for
                        
                          commons-lang:commons-lang
                        
                        (Maven)
                      Jul 11, 2025 
                    
                  
                    
                      Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53864
                      
                      was published
                        for
                        
                          com.nimbusds:nimbus-jose-jwt
                        
                        (Maven)
                      Jul 11, 2025 
                    
                  
                    
                      LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-5472
                      
                      was published
                        for
                        
                          llama-index-core
                        
                        (pip)
                      Jul 7, 2025 
                    
                  
                    
                      Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
                    
                      
  Moderate
                    
                
                      
                        GHSA-rxf6-323f-44fc
                      
                      was published
                        for
                        
                          protobuf
                        
                        (Rust)
                      Jul 5, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6710
                      
                      was published
                      Jun 26, 2025 
                    
                  
                    
                      protobuf-python has a potential Denial of Service issue
                    
                      
  High
                    
                
                      
                        CVE-2025-4565
                      
                      was published
                        for
                        
                          protobuf
                        
                        (pip)
                      Jun 16, 2025 
                    
                  
                    
                      In ims service, there is a possible system crash due to incorrect error handling. This could lead...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20678
                      
                      was published
                      Jun 2, 2025 
                    
                  
                    
                      In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30193
                      
                      was published
                      May 20, 2025 
                    
                  
                    
                      LlamaIndex Vulnerable to Denial of Service (DoS)
                    
                      
  High
                    
                
                      
                        CVE-2025-1752
                      
                      was published
                        for
                        
                          llama-index
                        
                        (pip)
                      May 10, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API