GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            87 advisories
        Filter by severity
        
      
      
    
                    
                      Keycloak TLS Client-Initiated Renegotiation Denial of Service
                    
                      
  High
                    
                
                      
                        CVE-2025-11419
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-quarkus-dist
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Undertow MadeYouReset HTTP/2 DDoS Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-9784
                      
                      was published
                        for
                        
                          io.undertow:undertow-core
                        
                        (Maven)
                      Sep 2, 2025 
                    
                  
                    
                      Liferay Portal users can upload an unlimited amount of files
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43762
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.dynamic.data.mapping.form.field.type
                        
                        (Maven)
                      Aug 22, 2025 
                    
                  
                    
                      Liferay Portal's Unlimited File Upload Could Result in DoS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43752
                      
                      was published
                        for
                        
                          com.liferay.portal:release.portal.bom
                        
                        (Maven)
                      Aug 22, 2025 
                    
                  
                    
                      Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-5115
                      
                      was published
                        for
                        
                          org.eclipse.jetty.http2:http2-common
                        
                        (Maven)
                      Aug 20, 2025 
                    
                  
                    
                      Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-55163
                      
                      was published
                        for
                        
                          io.grpc:grpc-netty-shaded
                        
                        (Maven)
                      Aug 13, 2025 
                    
                  
                    
                      Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-8916
                      
                      was published
                        for
                        
                          org.bouncycastle:bcpkix-fips
                        
                        (Maven)
                      Aug 13, 2025 
                    
                  
                    
                      Bouncy Castle for Java on All (API modules) allows Excessive Allocation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-8885
                      
                      was published
                        for
                        
                          org.bouncycastle:bc-fips
                        
                        (Maven)
                      Aug 12, 2025 
                    
                  
                    
                      Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43736
                      
                      was published
                        for
                        
                          com.liferay.portal:release.dxp.bom
                        
                        (Maven)
                      Aug 12, 2025 
                    
                  
                    
                      Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
                    
                      
  High
                    
                
                      
                        CVE-2025-48976
                      
                      was published
                        for
                        
                          commons-fileupload:commons-fileupload
                        
                        (Maven)
                      Jun 16, 2025 
                    
                  
                    
                      Apache Tomcat - DoS in multipart upload
                    
                      
  High
                    
                
                      
                        CVE-2025-48988
                      
                      was published
                        for
                        
                          org.apache.tomcat.embed:tomcat-embed-core
                        
                        (Maven)
                      Jun 16, 2025 
                    
                  
                    
                      Cuba has a DoS in the File Storage
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32959
                      
                      was published
                        for
                        
                          com.haulmont.cuba:cuba-core
                        
                        (Maven)
                      Apr 22, 2025 
                    
                  
                    
                      io.jmix.localfs:jmix-localfs affected by DoS in the Local File Storage
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32952
                      
                      was published
                        for
                        
                          io.jmix.localfs:jmix-localfs
                        
                        (Maven)
                      Apr 22, 2025 
                    
                  
                    
                      Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-2559
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-services
                        
                        (Maven)
                      Mar 25, 2025 
                    
                  
                    
                      H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
                    
                      
  High
                    
                
                      
                        CVE-2024-7768
                      
                      was published
                        for
                        
                          ai.h2o:h2o-core
                        
                        (Maven)
                      Mar 20, 2025 
                    
                  
                    
                      Apache James vulnerable to denial of service through the use of IMAP literals
                    
                      
  High
                    
                
                      
                        CVE-2024-37358
                      
                      was published
                        for
                        
                          org.apache.james.protocols:protocols-imap
                        
                        (Maven)
                      Feb 6, 2025 
                    
                  
                    
                      Elasticsearch allocation of resources without limits or throttling leads to crash
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-43709
                      
                      was published
                        for
                        
                          org.elasticsearch:elasticsearch
                        
                        (Maven)
                      Jan 21, 2025 
                    
                  
                    
                      Searching Opencast may cause a denial of service
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-52797
                      
                      was published
                        for
                        
                          org.opencastproject:opencast-elasticsearch-impl
                        
                        (Maven)
                      Nov 20, 2024 
                    
                  
                    
                      Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-38286
                      
                      was published
                        for
                        
                          org.apache.tomcat:tomcat-util
                        
                        (Maven)
                      Nov 7, 2024 
                    
                  
                    
                      Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
                    
                      
  Critical
                    
                
                      
                        CVE-2024-38821
                      
                      was published
                        for
                        
                          org.springframework.security:spring-security-web
                        
                        (Maven)
                      Oct 28, 2024 
                    
                  
                    
                      Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-8184
                      
                      was published
                        for
                        
                          org.eclipse.jetty:jetty-server
                        
                        (Maven)
                      Oct 14, 2024 
                    
                  
                    
                      Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
                    
                      
  Low
                    
                
                      
                        CVE-2024-6762
                      
                      was published
                        for
                        
                          org.eclipse.jetty:jetty-servlets
                        
                        (Maven)
                      Oct 14, 2024 
                    
                  
                    
                      Vertx gRPC server does not limit the maximum message size
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-8391
                      
                      was published
                        for
                        
                          io.vertx:vertx-grpc-client
                        
                        (Maven)
                      Sep 4, 2024 
                    
                  
                    
                      Spring Framework vulnerable to Denial of Service
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-38808
                      
                      was published
                        for
                        
                          org.springframework:spring-expression
                        
                        (Maven)
                      Aug 20, 2024 
                    
                  
                    
                      GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
                    
                      
  High
                    
                
                      
                        CVE-2024-40094
                      
                      was published
                        for
                        
                          com.graphql-java:graphql-java
                        
                        (Maven)
                      Jul 30, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API