GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
22 advisories
Filter by severity
fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the -...
Moderate
Unreviewed
CVE-2026-53433
was published
Jun 30, 2026
unicodedata.normalize() can take excessive CPU time when processing
specially crafted Unicode...
Moderate
Unreviewed
CVE-2026-3276
was published
Jun 3, 2026
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies...
Moderate
Unreviewed
CVE-2026-44390
was published
May 20, 2026
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator...
Moderate
Unreviewed
CVE-2026-42923
was published
May 20, 2026
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service...
Moderate
Unreviewed
CVE-2026-41292
was published
May 20, 2026
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU ...
Moderate
Unreviewed
CVE-2025-14831
was published
Feb 9, 2026
When building nested elements using xml.dom.minidom methods such as appendChild() that have a...
Moderate
Unreviewed
CVE-2025-12084
was published
Dec 3, 2025
Due to the design of the name constraint checking algorithm, the processing time of some inputs...
Moderate
Unreviewed
CVE-2025-58187
was published
Oct 30, 2025
encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and...
Moderate
Unreviewed
CVE-2025-30348
was published
Mar 21, 2025
A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka...
Moderate
Unreviewed
CVE-2025-24947
was published
Feb 20, 2025
The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function,...
Moderate
Unreviewed
CVE-2025-24946
was published
Feb 20, 2025
A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a...
Moderate
Unreviewed
CVE-2024-12133
was published
Feb 10, 2025
A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an...
Moderate
Unreviewed
CVE-2024-12243
was published
Feb 10, 2025
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5...
Moderate
Unreviewed
CVE-2024-6324
was published
Jan 9, 2025
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior...
Moderate
Unreviewed
CVE-2024-8237
was published
Nov 26, 2024
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13...
Moderate
Unreviewed
CVE-2024-11828
was published
Nov 26, 2024
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5...
Moderate
Unreviewed
CVE-2024-8177
was published
Nov 26, 2024
A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco ...
Moderate
Unreviewed
CVE-2020-3548
was published
Nov 18, 2024
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during...
Moderate
Unreviewed
CVE-2024-39702
was published
Jul 23, 2024
The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock...
Moderate
Unreviewed
CVE-2024-29916
was published
Mar 21, 2024
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This...
Moderate
Unreviewed
CVE-2023-2473
was published
May 2, 2023
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple...
Moderate
Unreviewed
CVE-2019-15955
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API