GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
197 advisories
Filter by severity
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
High
CVE-2026-59935
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
High
CVE-2026-59901
was published
for
io.netty:netty-codec
(Maven)
Jul 22, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Moderate
CVE-2026-59203
was published
for
pillow
(pip)
Jul 20, 2026
protobufjs: Denial of Service via infinite loop in .proto option parsing
Moderate
CVE-2026-59877
was published
for
protobufjs
(npm)
Jul 20, 2026
node-tar: Negative tar entry size causes infinite loop in archive replace
High
CVE-2026-59874
was published
for
tar
(npm)
Jul 20, 2026
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
High
GHSA-xf7x-x43h-rpqh
was published
for
json-repair
(pip)
Jul 13, 2026
pypdf: Possible infinite loop when processing threads/articles in writer
Moderate
CVE-2026-54651
was published
for
pypdf
(pip)
Jul 9, 2026
OpenStack Swift: s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body
High
CVE-2026-49017
was published
for
swift
(pip)
May 27, 2026
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
High
CVE-2026-47066
was published
for
hackney
(Erlang)
Jun 26, 2026
ImageMagick has an Infinite Loop in subimage-search with crafted image
Moderate
CVE-2026-48733
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
High
CVE-2026-54904
was published
for
concurrent-ruby
(RubyGems)
Jun 19, 2026
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
High
CVE-2026-54772
was published
for
CoreWCF.NetFramingBase
(NuGet)
Jun 19, 2026
Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
Moderate
CVE-2026-55865
was published
for
python-liquid
(pip)
Jun 19, 2026
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
Moderate
CVE-2026-54531
was published
for
pypdf
(pip)
Jun 16, 2026
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
Moderate
CVE-2026-54530
was published
for
pypdf
(pip)
Jun 16, 2026
Infinite Loop in Apache Tomcat
High
CVE-2020-13935
was published
for
org.apache.tomcat.embed:tomcat-embed-websocket
(Maven)
Feb 8, 2022
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
Moderate
CVE-2026-46521
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
High
CVE-2026-46522
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
image-size Denial of Service via Infinite Loop during Image Processing
High
CVE-2025-71319
was published
for
image-size
(npm)
Apr 2, 2025
ProTip!
Advisories are also available from the
GraphQL API