GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
358 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
bonding: prevent potential...
High
Unreviewed
CVE-2026-23451
was published
Apr 3, 2026
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
High
CVE-2026-59935
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
High
Unreviewed
CVE-2026-56852
was published
Jul 21, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote...
High
Unreviewed
CVE-2026-4890
was published
May 11, 2026
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an...
High
Unreviewed
CVE-2026-64611
was published
Jul 23, 2026
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
High
CVE-2026-59901
was published
for
io.netty:netty-codec
(Maven)
Jul 22, 2026
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer...
High
Unreviewed
CVE-2026-64834
was published
Jul 22, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
node-tar: Negative tar entry size causes infinite loop in archive replace
High
CVE-2026-59874
was published
for
tar
(npm)
Jul 20, 2026
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users...
High
Unreviewed
CVE-2025-71397
was published
Jul 18, 2026
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed...
High
Unreviewed
CVE-2026-13401
was published
Jul 16, 2026
HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed...
High
Unreviewed
CVE-2026-13397
was published
Jul 16, 2026
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services ...
High
Unreviewed
CVE-2026-50647
was published
Jul 14, 2026
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an...
High
Unreviewed
CVE-2026-54119
was published
Jul 14, 2026
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
High
GHSA-xf7x-x43h-rpqh
was published
for
json-repair
(pip)
Jul 13, 2026
In the Linux kernel, the following vulnerability has been resolved:
io_uring/poll: fix signed...
High
Unreviewed
CVE-2026-52933
was published
Jun 24, 2026
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server
to trigger a remote...
High
Unreviewed
CVE-2026-11352
was published
Jul 3, 2026
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
High
Unreviewed
CVE-2022-23352
was published
Mar 22, 2022
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
High
CVE-2026-49017
was published
for
swift
(pip)
May 27, 2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
High
Unreviewed
CVE-2026-34282
was published
Apr 21, 2026
A flaw was identified in the RAR5 archive decompression logic of the libarchive library,...
High
Unreviewed
CVE-2026-4111
was published
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API