Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

43 advisories

Loading
league/commonmark: Denial of service via deeply nested XML output Moderate
GHSA-mj63-m3rc-8ppr was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
Nerdbank.MessagePack has a memory amplification DoS in collection deserialization Moderate
GHSA-qjvr-435c-5fjh was published for Nerdbank.MessagePack (NuGet) May 29, 2026
svenclaesson Credited to svenclaesson and AArnott AArnott AArnott
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling Moderate
GHSA-36cp-mh65-x882 was published for openclaw (npm) Apr 10, 2026 withdrawn
Bitcoin Core through 29.0 allows a denial of service via a crafted transaction. Moderate Unreviewed
CVE-2025-46598 was published Mar 20, 2026
Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse High
CVE-2026-22774 was published for devalue (npm) Jan 15, 2026
jviide Credited to jviide, elliott-with-the-longest-name-on-github, and Rich-Harris elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
Rich-Harris Rich-Harris
devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse High
CVE-2026-22775 was published for devalue (npm) Jan 15, 2026
jviide Credited to jviide, elliott-with-the-longest-name-on-github, and Rich-Harris elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
Rich-Harris Rich-Harris
Marshmallow has DoS in Schema.load(many) Moderate
CVE-2025-68480 was published for marshmallow (pip) Dec 22, 2025
SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security... Moderate Unreviewed
CVE-2025-42873 was published Dec 9, 2025
Sigstore Timestamp Authority allocates excessive memory during request parsing High
CVE-2025-66564 was published for github.com/sigstore/timestamp-authority (Go) Dec 5, 2025
Fulcio allocates excessive memory during token parsing High
CVE-2025-66506 was published for github.com/sigstore/fulcio (Go) Dec 5, 2025
adeinega Credited to adeinega
net-imap rubygem vulnerable to possible DoS by memory exhaustion Moderate
CVE-2025-43857 was published for net-imap (RubyGems) Apr 28, 2025
Masamuneee Credited to Masamuneee and nevans nevans nevans
ProTip! Advisories are also available from the GraphQL API