GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,783
Erlang
36
GitHub Actions
29
Go
2,353
Maven
5,000+
npm
3,977
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
180 advisories
Filter by severity
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
High
CVE-2025-48976
was published
for
org.apache.commons:commons-fileupload2-core
(Maven)
Jun 16, 2025
Apache Tomcat - DoS in multipart upload
High
CVE-2025-48988
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Drupal Admin Audit Trail Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-48448
was published
for
drupal/admin_audit_trail
(Composer)
Jun 11, 2025
Pion Interceptor's improper RTP padding handling allows remote crash for SFU users (DoS)
High
CVE-2025-49140
was published
for
github.com/pion/interceptor
(Go)
Jun 9, 2025
CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
High
CVE-2025-47950
was published
for
github.com/coredns/coredns
(Go)
Jun 6, 2025
Tornado vulnerable to excessive logging caused by malformed multipart form data
High
CVE-2025-47287
was published
for
tornado
(pip)
May 16, 2025
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin
High
CVE-2025-32777
was published
for
volcano.sh/volcano
(Go)
Apr 30, 2025
Data exposure via ZeroMQ on multi-node vLLM deployment
High
CVE-2025-30202
was published
for
vllm
(pip)
Apr 29, 2025
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
High
CVE-2025-22869
was published
for
golang.org/x/crypto
(Go)
Apr 12, 2025
Apollo Compiler Named Fragment Processing Vulnerability
High
CVE-2025-31496
was published
for
apollo-compiler
(Rust)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32031
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32030
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment Processing
High
CVE-2025-32380
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32034
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32032
was published
for
apollo-router
(Rust)
Apr 7, 2025
image-size Denial of Service via Infinite Loop during Image Processing
High
GHSA-m5qc-5hw7-8vg7
was published
for
image-size
(npm)
Apr 2, 2025
Nethermind Juno Potential Denial of Service (DoS) via Integer Overflow
High
CVE-2025-29072
was published
for
github.com/NethermindEth/juno
(Go)
Mar 27, 2025
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-0315
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High
CVE-2024-12537
was published
for
open-webui
(npm)
Mar 20, 2025
jsPDF Bypass Regular Expression Denial of Service (ReDoS)
High
CVE-2025-29907
was published
for
jspdf
(npm)
Mar 18, 2025
Memory Exhaustion in Expr Parser with Unrestricted Input
High
CVE-2025-29786
was published
for
github.com/expr-lang/expr
(Go)
Mar 17, 2025
Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
High
CVE-2025-25293
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
DoS Vulnerability in TraceContextPropagator.Extract - OpenTelemetry.Api
High
GHSA-vc29-vg52-6643
was published
for
OpenTelemetry.AutoInstrumentation
(NuGet)
Mar 6, 2025
ProTip!
Advisories are also available from the
GraphQL API