GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,330 advisories
Filter by severity
urllib3 allows an unbounded number of links in the decompression chain
High
CVE-2025-66418
was published
for
urllib3
(pip)
Dec 5, 2025
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity...
High
Unreviewed
CVE-2025-12385
was published
Dec 3, 2025
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to...
Moderate
Unreviewed
CVE-2025-63402
was published
Dec 3, 2025
Interactive service agent in OpenVPN version 2.5.0 through 2.7_rc2 on Windows allows a local...
Low
Unreviewed
CVE-2025-13751
was published
Dec 3, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5,...
High
Unreviewed
CVE-2025-12571
was published
Nov 26, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18...
Moderate
Unreviewed
CVE-2025-7449
was published
Nov 26, 2025
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
Low
CVE-2025-65942
was published
for
github.com/VictoriaMetrics/VictoriaMetrics
(Go)
Nov 25, 2025
Babylon's malformed vote extensions are not rejected
High
GHSA-2fcv-qww3-9v6h
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
Moderate
CVE-2025-62426
was published
for
vllm
(pip)
Nov 20, 2025
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
Moderate
CVE-2025-58181
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6...
High
Unreviewed
CVE-2025-11243
was published
Nov 19, 2025
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user...
Moderate
Unreviewed
CVE-2025-54320
was published
Nov 18, 2025
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
Critical
CVE-2025-65015
was published
for
joserfc
(pip)
Nov 18, 2025
EasyFlow GP developed by Digiwin has a Denial of service vulnerability, allowing unauthenticated...
High
Unreviewed
CVE-2025-13165
was published
Nov 17, 2025
SpiceDB WriteRelationships fails silently if payload is too big
Low
CVE-2025-64529
was published
for
github.com/authzed/spicedb
(Go)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
High
CVE-2025-64509
was published
for
bugsink
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
High
CVE-2025-64508
was published
for
bugsink
(pip)
Nov 13, 2025
If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through...
Moderate
Unreviewed
CVE-2025-59089
was published
Nov 12, 2025
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of...
Moderate
Unreviewed
CVE-2025-12748
was published
Nov 11, 2025
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2025-36008
was published
Nov 7, 2025
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes...
Moderate
Unreviewed
CVE-2025-36136
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-53411
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Moderate
Unreviewed
CVE-2025-53410
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Moderate
Unreviewed
CVE-2025-53413
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Moderate
Unreviewed
CVE-2025-53409
was published
Nov 7, 2025
ProTip!
Advisories are also available from the
GraphQL API