GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            19 advisories
        Filter by severity
        
      
      
    
                    
                      pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
                    
                      
  High
                    
                
                      
                        CVE-2025-11362
                      
                      was published
                        for
                        
                          pdfmake
                        
                        (npm)
                      Oct 7, 2025 
                    
                  
                    
                      Finance.js vulnerable to DoS via the seekZero() parameter
                    
                      
  High
                    
                
                      
                        CVE-2025-56572
                      
                      was published
                        for
                        
                          financejs
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      Finance.js vulnerable to DoS via the IRR function’s depth parameter
                    
                      
  High
                    
                
                      
                        CVE-2025-56571
                      
                      was published
                        for
                        
                          financejs
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      Axios is vulnerable to DoS attack through lack of data size check
                    
                      
  High
                    
                
                      
                        CVE-2025-58754
                      
                      was published
                        for
                        
                          axios
                        
                        (npm)
                      Sep 11, 2025 
                    
                  
                    
                      Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
                    
                      
  High
                    
                
                      
                        CVE-2025-32031
                      
                      was published
                        for
                        
                          @apollo/gateway
                        
                        (npm)
                      Apr 7, 2025 
                    
                  
                    
                      Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
                    
                      
  High
                    
                
                      
                        CVE-2025-32030
                      
                      was published
                        for
                        
                          @apollo/gateway
                        
                        (npm)
                      Apr 7, 2025 
                    
                  
                    
                      image-size Denial of Service via Infinite Loop during Image Processing
                    
                      
  High
                    
                
                      
                        GHSA-m5qc-5hw7-8vg7
                      
                      was published
                        for
                        
                          image-size
                        
                        (npm)
                      Apr 2, 2025 
                    
                  
                    
                      Open WebUI Uncontrolled Resource Consumption vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-12537
                      
                      was published
                        for
                        
                          open-webui
                        
                        (npm)
                      Mar 20, 2025 
                    
                  
                    
                      jsPDF Bypass Regular Expression Denial of Service (ReDoS)
                    
                      
  High
                    
                
                      
                        CVE-2025-29907
                      
                      was published
                        for
                        
                          jspdf
                        
                        (npm)
                      Mar 18, 2025 
                    
                  
                    
                      Unlimited consumption of resources in @fastify/multipart
                    
                      
  High
                    
                
                      
                        CVE-2025-24033
                      
                      was published
                        for
                        
                          @fastify/multipart
                        
                        (npm)
                      Jan 23, 2025 
                    
                  
                    
                      Strapi Improper Rate Limiting vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2023-38507
                      
                      was published
                        for
                        
                          @strapi/admin
                        
                        (npm)
                      Sep 13, 2023 
                    
                  
                    
                      Denial of service due to unlimited number of parts
                    
                      
  High
                    
                
                      
                        CVE-2023-25576
                      
                      was published
                        for
                        
                          @fastify/multipart
                        
                        (npm)
                      Feb 14, 2023 
                    
                  
                    
                      libp2p DoS vulnerability from lack of resource management
                    
                      
  High
                    
                
                      
                        CVE-2022-23487
                      
                      was published
                        for
                        
                          libp2p
                        
                        (npm)
                      Dec 7, 2022 
                    
                  
                    
                      node-opcua DoS vulnerability via message with memory allocation that exceeds v8's memory limit
                    
                      
  High
                    
                
                      
                        CVE-2022-25231
                      
                      was published
                        for
                        
                          node-opcua
                        
                        (npm)
                      Aug 24, 2022 
                    
                  
                    
                      modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests
                    
                      
  High
                    
                
                      
                        CVE-2021-41167
                      
                      was published
                        for
                        
                          modern-async
                        
                        (npm)
                      Oct 21, 2021 
                    
                  
                    
                      Regular Expression Denial of Service in sshpk
                    
                      
  High
                    
                
                      
                        CVE-2018-3737
                      
                      was published
                        for
                        
                          sshpk
                        
                        (npm)
                      Aug 15, 2018 
                    
                  
                    
                      Denial of Service vulnerability with large JSON payloads in fastify
                    
                      
  High
                    
                
                      
                        CVE-2018-3711
                      
                      was published
                        for
                        
                          fastify
                        
                        (npm)
                      Jul 18, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API