GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,227 advisories
Filter by severity
An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2...
Moderate
Unreviewed
CVE-2025-1250
was published
Sep 12, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2...
Moderate
Unreviewed
CVE-2025-7337
was published
Sep 12, 2025
Axios is vulnerable to DoS attack through lack of data size check
High
CVE-2025-58754
was published
for
axios
(npm)
Sep 11, 2025
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote...
Moderate
Unreviewed
CVE-2024-45669
was published
Sep 10, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
xgrammar vulnerable to denial of service by huge enum grammar
Moderate
CVE-2025-58446
was published
for
xgrammar
(pip)
Sep 5, 2025
The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service ...
High
Unreviewed
CVE-2014-125127
was published
Sep 3, 2025
PocketMine-MP `ResourcePackDataInfoPacket` amplification vulnerability due to lack of resource pack sequence status checking
High
GHSA-fqqv-56h5-f57g
was published
for
pocketmine/pocketmine-mp
(Composer)
Sep 2, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-30260
was published
Aug 29, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-30261
was published
Aug 29, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-29890
was published
Aug 29, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-29900
was published
Aug 29, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-29899
was published
Aug 29, 2025
Rancher affected by unauthenticated Denial of Service
High
CVE-2024-58259
was published
for
github.com/rancher/rancher
(Go)
Aug 29, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads
High
CVE-2025-6203
was published
for
github.com/hashicorp/vault
(Go)
Aug 28, 2025
github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
Moderate
CVE-2025-58058
was published
for
github.com/ulikunitz/xz
(Go)
Aug 28, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2...
Moderate
Unreviewed
CVE-2025-3601
was published
Aug 27, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2...
Moderate
Unreviewed
CVE-2025-4225
was published
Aug 27, 2025
Liferay Portal users can upload an unlimited amount of files
Moderate
CVE-2025-43762
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Aug 22, 2025
Liferay Portal's Unlimited File Upload Could Result in DoS
Moderate
CVE-2025-43752
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 22, 2025
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
High
CVE-2025-5115
was published
for
org.eclipse.jetty.http2:http2-common
(Maven)
Aug 20, 2025
CRI-O has Potential High Memory Consumption from File Read
Moderate
CVE-2025-4437
was published
for
github.com/cri-o/cri-o
(Go)
Aug 20, 2025
IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of...
Moderate
Unreviewed
CVE-2025-36047
was published
Aug 14, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
Moderate
CVE-2025-55199
was published
for
helm.sh/helm/v3
(Go)
Aug 14, 2025
PyPDF's Manipulated FlateDecode streams can exhaust RAM
Moderate
CVE-2025-55197
was published
for
pypdf
(pip)
Aug 13, 2025
ProTip!
Advisories are also available from the
GraphQL API