GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
21 advisories
Filter by severity
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
High
CVE-2026-87011
was published
for
open-webui
(pip)
Sep 10, 2026
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Moderate
CVE-2026-84310
was published
for
pypdf
(pip)
Sep 1, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
league/commonmark: Denial of service via deeply nested XML output
Moderate
GHSA-mj63-m3rc-8ppr
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization
Moderate
GHSA-qjvr-435c-5fjh
was published
for
Nerdbank.MessagePack
(NuGet)
May 29, 2026
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
Moderate
GHSA-36cp-mh65-x882
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw has incomplete Fix for CVE-2026-32011: Feishu Webhook Pre-Auth Body Parsing DoS (Slow-Body / Slowloris Variant)
Moderate
CVE-2026-35665
was published
for
openclaw
(npm)
Mar 30, 2026
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse
High
CVE-2026-22775
was published
for
devalue
(npm)
Jan 15, 2026
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse
High
CVE-2026-22774
was published
for
devalue
(npm)
Jan 15, 2026
Marshmallow has DoS in Schema.load(many)
Moderate
CVE-2025-68480
was published
for
marshmallow
(pip)
Dec 22, 2025
Sigstore Timestamp Authority allocates excessive memory during request parsing
High
CVE-2025-66564
was published
for
github.com/sigstore/timestamp-authority
(Go)
Dec 5, 2025
Fulcio allocates excessive memory during token parsing
High
CVE-2025-66506
was published
for
github.com/sigstore/fulcio
(Go)
Dec 5, 2025
swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability
Moderate
GHSA-xvr7-p2c6-j83w
was published
for
github.com/apple/swift-nio-http2
(Swift)
Aug 13, 2025
Chall-Manager's scenario decoding process does not check for zip bombs
High
CVE-2025-53633
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
jwt-go allows excessive memory allocation during header parsing
High
CVE-2025-30204
was published
for
github.com/golang-jwt/jwt
(Go)
Mar 21, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
body-parser vulnerable to denial of service when url encoding is enabled
High
CVE-2024-45590
was published
for
body-parser
(npm)
Sep 10, 2024
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling
Moderate
CVE-2022-23500
was published
for
typo3/cms
(Composer)
Dec 13, 2022
Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings
Moderate
CVE-2021-32699
was published
for
github.com/pterodactyl/wings
(Go)
Jun 23, 2021
Denial of Service in Page Error Handling
Moderate
CVE-2021-21359
was published
for
typo3/cms
(Composer)
Mar 23, 2021
ProTip!
Advisories are also available from the
GraphQL API