Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

66 advisories

Loading
openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions High
CVE-2023-0216 was published for openssl-src (Rust) Feb 8, 2023
openssl-src contains `NULL` dereference during PKCS7 data verification High
CVE-2023-0401 was published for openssl-src (Rust) Feb 8, 2023
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload High
CVE-2025-59537 was published for github.com/argoproj/argo-cd (Go) Sep 30, 2025
s0ngsari530 jake-ciolek
crenshaw-dev blakepettersson
Credited to s0ngsari530, jake-ciolek, crenshaw-dev, and blakepettersson
Nil dereference in NATS JWT, DoS of nats-server High
CVE-2020-26521 was published for github.com/nats-io/jwt (Go) Feb 11, 2022
Nil dereference in NATS JWT causing DoS of nats-server High
GHSA-hmm9-r2m2-qg9w was published for github.com/nats-io/nats-server/v2 (Go) May 21, 2021
@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user High
CVE-2025-61668 was published for @plone/volto (npm) Oct 1, 2025
Versity panic induced by AWS chunked data sent to port High
GHSA-v2ch-c8v8-fgr7 was published for github.com/versity/versitygw (Go) Aug 29, 2025
tonyipm
Credited to tonyipm
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers High
CVE-2021-22570 was published for Google.Protobuf (Composer) Jan 27, 2022 withdrawn
joshbressers
Credited to joshbressers
Ollama Denial of Service (DoS) via Null Pointer Dereference High
CVE-2025-0312 was published for github.com/ollama/ollama (Go) Mar 20, 2025
openssl-src subject to NULL dereference validating DSA public key High
CVE-2023-0217 was published for openssl-src (Rust) Feb 8, 2023
Alexander-Programming cd-work
Credited to Alexander-Programming and cd-work
bounter Null pointer reference High
CVE-2021-41497 was published for bounter (pip) Dec 18, 2021
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request High
CVE-2024-0793 was published for k8s.io/kubernetes (Go) Nov 17, 2024
VTK NULL pointer dereference vulnerability High
CVE-2021-42521 was published for vtk (pip) Aug 26, 2022
Null-dereference in Tensorflow High
CVE-2022-23577 was published for tensorflow (pip) Feb 10, 2022
Null-dereference in Tensorflow High
CVE-2022-23570 was published for tensorflow (pip) Feb 9, 2022
Null pointer dereference in TensorFlow High
CVE-2022-21739 was published for tensorflow (pip) Feb 9, 2022
Undefined behavior in `SparseTensorSliceDataset` High
CVE-2022-21736 was published for tensorflow (pip) Feb 9, 2022
Null pointer dereference in TFLite MLIR optimizations High
CVE-2021-37689 was published for tensorflow (pip) Aug 25, 2021
KateCatlin
Credited to KateCatlin
Null pointer dereference in TFLite High
CVE-2021-37688 was published for tensorflow (pip) Aug 25, 2021
NPE in TFLite High
CVE-2021-37681 was published for tensorflow (pip) Aug 25, 2021
Null pointer dereference in `UncompressElement` High
CVE-2021-37649 was published for tensorflow (pip) Aug 25, 2021
Incorrect validation of `SaveV2` inputs High
CVE-2021-37648 was published for tensorflow (pip) Aug 25, 2021
Null pointer dereference in `SparseTensorSliceDataset` High
CVE-2021-37647 was published for tensorflow (pip) Aug 25, 2021
Null pointer dereference in `CompressElement` High
CVE-2021-37637 was published for tensorflow (pip) Aug 25, 2021
ProTip! Advisories are also available from the GraphQL API