GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,438 advisories
Filter by severity
Denial of Service in markdown-it-toc-and-anchor
High
GHSA-x6m6-5hrf-fh6r
was published
for
markdown-it-toc-and-anchor
(npm)
Sep 1, 2020
Denial of Service in @hapi/subtext
High
GHSA-4rgj-8mq3-hggj
was published
for
@hapi/subtext
(npm)
Sep 3, 2020
Denial of Service in @commercial/subtext
High
GHSA-fvwr-h9xh-m6wc
was published
for
@commercial/subtext
(npm)
Sep 3, 2020
Bitcoin Inventory Out-of-Memory Denial-of-Service Attack (CVE-2018-17145)
High
CVE-2018-17145
was published
for
bcoin
(npm)
Sep 10, 2020
Exploitable inventory component chaining in PocketMine-MP
High
GHSA-8jq6-w5cg-wm45
was published
for
pocketmine/pocketmine-mp
(Composer)
Nov 11, 2020
Denial of service attack via incorrect parameters in Matrix Synapse
High
CVE-2020-26257
was published
for
matrix-synapse
(pip)
Dec 9, 2020
regular expression denial of service (ReDoS)
High
CVE-2020-26289
was published
for
date-and-time
(npm)
Dec 24, 2020
Regular Expression Denial of Service in CairoSVG
High
CVE-2021-21236
was published
for
CairoSVG
(pip)
Jan 6, 2021
Regular Expression Denial of Service in jquery-validation
High
CVE-2021-21252
was published
for
jQuery.Validation
(npm)
Jan 13, 2021
Prototype pollution in nested-object-assign
High
CVE-2021-23329
was published
for
nested-object-assign
(npm)
Feb 1, 2021
Unbounded connection acceptance leads to file handle exhaustion
High
CVE-2021-21293
was published
for
org.http4s:blaze-core_2.11
(Maven)
Feb 2, 2021
Unbounded connection acceptance in http4s-blaze-server
High
CVE-2021-21294
was published
for
org.http4s:http4s-blaze-server_2.12
(Maven)
Feb 2, 2021
Regular Expression Denial of Service (REDoS) in httplib2
High
CVE-2021-21240
was published
for
httplib2
(pip)
Feb 8, 2021
Active Record subject to Regular Expression Denial-of-Service (ReDoS)
High
CVE-2021-22880
was published
for
activerecord
(RubyGems)
Mar 2, 2021
jspdf vulnerable to Regular Expression Denial of Service (ReDoS)
High
CVE-2021-23353
was published
for
jspdf
(npm)
Mar 12, 2021
Uncontrolled Resource Consumption in Apache Thrift
High
CVE-2020-13949
was published
for
org.apache.thrift:libthrift
(Maven)
Mar 12, 2021
ProTip!
Advisories are also available from the
GraphQL API