GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,374
Erlang
33
GitHub Actions
22
Go
2,139
Maven
5,000+
npm
3,800
NuGet
687
pip
3,478
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
275 advisories
Filter by severity
Apache ActiveMQ Artemis Uncontrolled Resource Consumption (DoS)
High
CVE-2022-23913
was published
for
org.apache.activemq:artemis-core-client
(Maven)
Feb 6, 2022
Allocation of Resources Without Limits or Throttling in iText
Moderate
CVE-2022-24196
was published
for
com.itextpdf:itext7-core
(Maven)
Feb 2, 2022
android-gif-drawable vulerable to denial of service due to unrestricted comment length
High
CVE-2022-23435
was published
for
pl.droidsonroids.gif:android-gif-drawable
(Maven)
Jan 20, 2022
Allocation of Resources Without Limits or Throttling in Apache Avro
High
CVE-2021-43045
was published
for
Apache.Avro
(NuGet)
Jan 8, 2022
Allocation of Resources Without Limits or Throttling in ckb
High
CVE-2021-45699
was published
for
ckb
(Rust)
Jan 6, 2022
ReDOS in Vfsjfilechooser2
High
CVE-2021-29061
was published
for
com.github.fracpete:vfsjfilechooser2
(Maven)
Jan 6, 2022
Denial of Service (DoS) in Jackson Dataformat CBOR
High
CVE-2020-28491
was published
for
com.fasterxml.jackson.dataformat:jackson-dataformat-cbor
(Maven)
Dec 9, 2021
OctoRPKI crashes when processing GZIP bomb returned via malicious repository
Moderate
CVE-2021-3912
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests
High
CVE-2021-41167
was published
for
modern-async
(npm)
Oct 21, 2021
Uncontrolled memory consumption in protobuf
High
CVE-2019-15544
was published
for
protobuf
(Rust)
Aug 25, 2021
Improper Handling of Length Parameter Inconsistency in Compress
High
CVE-2021-35517
was published
for
org.apache.commons:commons-compress
(Maven)
Aug 2, 2021
Improper Handling of Length Parameter Inconsistency in Compress
High
CVE-2021-35516
was published
for
org.apache.commons:commons-compress
(Maven)
Aug 2, 2021
Allocation of resources without limits or throttling in keycloak-model-infinispan
High
CVE-2021-3637
was published
for
org.keycloak:keycloak-model-infinispan
(Maven)
Jul 13, 2021
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Moderate
CVE-2021-32699
was published
for
github.com/pterodactyl/wings
(Go)
Jun 23, 2021
Regular Expression Denial of Service (ReDOS)
Moderate
CVE-2021-29060
was published
for
color-string
(npm)
Jun 22, 2021
Uncontrolled memory consumption
Moderate
CVE-2021-31811
was published
for
org.apache.pdfbox:pdfbox
(Maven)
Jun 15, 2021
Denial of service in direct_mail
Moderate
CVE-2020-12697
was published
for
directmailteam/direct-mail
(Composer)
May 24, 2021
Allocation of Resources Without Limits or Throttling in Hashicorp Consul
High
CVE-2020-13250
was published
for
github.com/hashicorp/consul
(Go)
May 18, 2021
Allocation of Resources Without Limits or Throttling in HashiCorp Nomad
High
CVE-2020-7218
was published
for
github.com/hashicorp/nomad
(Go)
May 18, 2021
Denial of Service (DoS) in HashiCorp Consul
High
CVE-2020-7219
was published
for
github.com/hashicorp/consul
(Go)
May 18, 2021
ProTip!
Advisories are also available from the
GraphQL API