GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
668
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
67 advisories
Filter by severity
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects...
High
Unreviewed
CVE-2021-42717
was published
Dec 8, 2021
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager,...
High
Unreviewed
CVE-2022-28773
was published
Apr 13, 2022
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream:...
High
Unreviewed
CVE-2019-9543
was published
May 13, 2022
An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream:...
High
Unreviewed
CVE-2019-9545
was published
May 13, 2022
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1...
High
Unreviewed
CVE-2018-6003
was published
May 13, 2022
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of...
High
Unreviewed
CVE-2017-9438
was published
May 13, 2022
In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion...
High
Unreviewed
CVE-2017-11164
was published
May 13, 2022
Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an...
High
Unreviewed
CVE-2019-0001
was published
May 13, 2022
An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image:...
High
Unreviewed
CVE-2019-9143
was published
May 13, 2022
An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in...
High
Unreviewed
CVE-2019-9144
was published
May 13, 2022
** DISPUTED ** In the GNU C Library (aka glibc or libc6) through 2.29,...
High
Unreviewed
CVE-2019-9192
was published
May 13, 2022
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix...
High
Unreviewed
CVE-2018-20796
was published
May 13, 2022
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not...
High
Unreviewed
CVE-2016-9597
was published
May 13, 2022
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc)...
High
Unreviewed
CVE-2017-11554
was published
May 13, 2022
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser...
High
Unreviewed
CVE-2017-11556
was published
May 13, 2022
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval:...
High
Unreviewed
CVE-2017-12964
was published
May 13, 2022
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in...
High
Unreviewed
CVE-2017-5839
was published
May 13, 2022
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of...
High
Unreviewed
CVE-2017-9304
was published
May 13, 2022
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause...
High
Unreviewed
CVE-2017-9766
was published
May 13, 2022
In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the...
High
Unreviewed
CVE-2017-9729
was published
May 13, 2022
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name...
High
Unreviewed
CVE-2018-9918
was published
May 13, 2022
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery...
High
Unreviewed
CVE-2016-3627
was published
May 14, 2022
An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match...
High
Unreviewed
CVE-2019-11413
was published
May 24, 2022
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions...
High
Unreviewed
CVE-2019-13123
was published
May 24, 2022
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions...
High
Unreviewed
CVE-2019-13124
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API