GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
373 advisories
Filter by severity
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
CVE-2026-73561
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
CVE-2026-73413
was published
for
shescape
(npm)
Jul 24, 2026
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
High
CVE-2026-71314
was published
for
nuxt
(npm)
Aug 5, 2026
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
High
CVE-2026-69152
was published
for
brace-expansion
(npm)
Aug 3, 2026
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
High
CVE-2026-14257
was published
for
brace-expansion
(npm)
Jul 24, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
react-server-dom: Denial of Service in Server Functions
High
CVE-2026-44907
was published
for
react-server-dom-parcel
(npm)
Jul 24, 2026
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
Moderate
GHSA-r292-9mhp-454m
was published
for
tar
(npm)
Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
Moderate
GHSA-mwf2-3pr3-8698
was published
for
axios
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
High
CVE-2026-13149
was published
for
brace-expansion
(npm)
Jul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
Moderate
GHSA-42h9-826w-cgv3
was published
for
axios
(npm)
Jul 20, 2026
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Moderate
GHSA-pmv8-rq9r-6j72
was published
for
axios
(npm)
Jul 20, 2026
adm-zip: Crafted ZIP file triggers 4GB memory allocation
High
CVE-2026-39244
was published
for
adm-zip
(npm)
Jul 10, 2026
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50272
was published
for
dd-trace
(npm)
Jul 15, 2026
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
High
CVE-2026-50171
was published
for
@angular/common
(npm)
Jun 15, 2026
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
High
CVE-2026-54268
was published
for
@angular/common
(npm)
Jun 15, 2026
Keystone: GraphQL API Endpoint Lacks Query Depth Limits
Low
CVE-2026-10802
was published
for
@keystone-6/core
(npm)
Jun 4, 2026
ws: Memory exhaustion DoS from tiny fragments and data chunks
High
CVE-2026-48779
was published
for
ws
(npm)
Jun 15, 2026
ProTip!
Advisories are also available from the
GraphQL API