GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            945 advisories
        Filter by severity
        
      
      
    
                    
                      gnark-crypto allows unchecked memory allocation during vector deserialization
                    
                      
  High
                    
                
                      
                        GHSA-fj2x-735w-74vq
                      
                      was published
                        for
                        
                          github.com/consensys/gnark-crypto
                        
                        (Go)
                      Oct 30, 2025 
                    
                  
                    
                      Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
                    
                      
  High
                    
                
                      
                        CVE-2025-62727
                      
                      was published
                        for
                        
                          starlette
                        
                        (pip)
                      Oct 28, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to DoS via Crafted Headless API Request
                    
                      
  High
                    
                
                      
                        CVE-2025-62260
                      
                      was published
                        for
                        
                          com.liferay.portal:release.portal.bom
                        
                        (Maven)
                      Oct 28, 2025 
                    
                  
                    
                      Keycloak TLS Client-Initiated Renegotiation Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2025-11419
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-quarkus-dist
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-12194
                      
                      was published
                        for
                        
                          org.bouncycastle:bc-fips
                        
                        (Maven)
                      Oct 25, 2025 
                    
                  
                    
                      ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-60790
                      
                      was published
                        for
                        
                          processwire/processwire
                        
                        (Composer)
                      Oct 21, 2025 
                    
                  
                    
                      OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
                    
                      
  High
                    
                
                      
                        CVE-2025-59043
                      
                      was published
                        for
                        
                          github.com/openbao/openbao
                        
                        (Go)
                      Oct 17, 2025 
                    
                  
                    
                      Parallax is vulnerable to DoS via malicious p2p message
                    
                      
  High
                    
                
                      
                        GHSA-xc79-566c-j4qx
                      
                      was published
                        for
                        
                          github.com/microstack-tech/parallax
                        
                        (Go)
                      Oct 10, 2025 
                    
                  
                    
                      Authlib : JWE zip=DEF decompression bomb enables DoS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62706
                      
                      was published
                        for
                        
                          authlib
                        
                        (pip)
                      Oct 10, 2025 
                    
                  
                    
                      Sinatra is vulnerable to ReDoS through ETag header value generation
                    
                      
  Low
                    
                
                      
                        CVE-2025-61921
                      
                      was published
                        for
                        
                          sinatra
                        
                        (RubyGems)
                      Oct 10, 2025 
                    
                  
                    
                      Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
                    
                      
  High
                    
                
                      
                        CVE-2025-61920
                      
                      was published
                        for
                        
                          authlib
                        
                        (pip)
                      Oct 10, 2025 
                    
                  
                    
                      Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
                    
                      
  High
                    
                
                      
                        CVE-2025-61919
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 10, 2025 
                    
                  
                    
                      Amazon.IonDotnet is vulnerable to Denial of Service attacks
                    
                      
  High
                    
                
                      
                        CVE-2025-11573
                      
                      was published
                        for
                        
                          Amazon.IonDotnet
                        
                        (NuGet)
                      Oct 9, 2025 
                    
                  
                    
                      vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61620
                      
                      was published
                        for
                        
                          vllm
                        
                        (pip)
                      Oct 7, 2025 
                    
                  
                    
                      Rack's multipart parser buffers unbounded per-part headers, enabling DoS (memory exhaustion)
                    
                      
  High
                    
                
                      
                        CVE-2025-61772
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 7, 2025 
                    
                  
                    
                      Rack: Multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
                    
                      
  High
                    
                
                      
                        CVE-2025-61771
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 7, 2025 
                    
                  
                    
                      Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
                    
                      
  High
                    
                
                      
                        CVE-2025-61770
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 7, 2025 
                    
                  
                    
                      github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
                    
                      
  High
                    
                
                      
                        CVE-2025-61595
                      
                      was published
                        for
                        
                          github.com/MANTRA-Chain/mantrachain
                        
                        (Go)
                      Sep 30, 2025 
                    
                  
                    
                      Finance.js vulnerable to DoS via the seekZero() parameter
                    
                      
  High
                    
                
                      
                        CVE-2025-56572
                      
                      was published
                        for
                        
                          financejs
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      Finance.js vulnerable to DoS via the IRR function’s depth parameter
                    
                      
  High
                    
                
                      
                        CVE-2025-56571
                      
                      was published
                        for
                        
                          financejs
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      @nubosoftware/node-static failure to catch exception can result in server crash
                    
                      
  High
                    
                
                      
                        CVE-2025-11149
                      
                      was published
                        for
                        
                          @nubosoftware/node-static
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      Rack has an unsafe default in Rack::QueryParser allows params_limit bypass via semicolon-separated parameters
                    
                      
  High
                    
                
                      
                        CVE-2025-59830
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Sep 25, 2025 
                    
                  
                    
                      apidoc-core is vulnerable to prototype pollution
                    
                      
  High
                    
                
                      
                        CVE-2025-57317
                      
                      was published
                        for
                        
                          apidoc-core
                        
                        (npm)
                      Sep 25, 2025 
                    
                  
                    
                      Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-6921
                      
                      was published
                        for
                        
                          transformers
                        
                        (pip)
                      Sep 23, 2025 
                    
                  
                    
                      REXML has DoS condition when parsing malformed XML file
                    
                      
  Low
                    
                
                      
                        CVE-2025-58767
                      
                      was published
                        for
                        
                          rexml
                        
                        (RubyGems)
                      Sep 17, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API