GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,988
Maven
5,000+
npm
3,704
NuGet
661
pip
3,332
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation
Moderate
CVE-2018-11797
was published
for
org.apache.pdfbox:pdfbox
(Maven)
Oct 17, 2018
DOS vulnerability for Quoted Quality CSV headers
Moderate
CVE-2020-27223
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Mar 10, 2021
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
Moderate
CVE-2021-21348
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Mar 22, 2021
Uncontrolled Resource Consumption in Apache Tika
Moderate
CVE-2020-1950
was published
for
org.apache.tika:tika
(Maven)
May 7, 2021
Infinite loop in Apache Tika
Moderate
CVE-2021-28657
was published
for
org.apache.tika:tika
(Maven)
May 10, 2021
Navigate endpoint is vulnerable to regex injection that may lead to Denial of Service.
Moderate
CVE-2021-29506
was published
for
com.graphhopper:graphhopper-nav
(Maven)
May 19, 2021
Uncontrolled Resource Consumption in XNIO
Moderate
CVE-2020-14340
was published
for
org.jboss.xnio:xnio-nio
(Maven)
Jun 8, 2021
Uncontrolled Resource Consumption in JPA Server in HAPI FHIR
Moderate
CVE-2021-32053
was published
for
ca.uhn.hapi.fhir:hapi-fhir-jpaserver-base
(Maven)
Jun 16, 2021
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32014
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Denial of Service in SheetsJS Pro
Moderate
CVE-2021-32013
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32012
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Denial of service in DataCommunicator class in Vaadin 8
Moderate
CVE-2021-33609
was published
for
com.vaadin:vaadin-server
(Maven)
Oct 13, 2021
Denial of service in DataCommunicator class in Vaadin 8
Moderate
GHSA-j23j-q57m-63v3
was published
for
com.vaadin:vaadin-server
(Maven)
Oct 13, 2021
A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft OpenSessionRequest messages.
Moderate
CVE-2020-35210
was published
for
io.atomix:atomix
(Maven)
Dec 17, 2021
Hash collision in typelevel jawn
Moderate
CVE-2022-21653
was published
for
org.typelevel:jawn-parser
(Maven)
Jan 6, 2022
Memory leak in micronaut-core
Moderate
CVE-2022-21700
was published
for
io.micronaut:micronaut-http
(Maven)
Jan 21, 2022
Denial of service in Spring Security OAuth2
Moderate
CVE-2022-22969
was published
for
org.springframework.security.oauth:spring-security-oauth2
(Maven)
Apr 22, 2022
Jakarta Tomcat Denial of Service vulnerability
Moderate
CVE-2003-0045
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 29, 2022
Apache Tomcat Denial of Service vulnerability in the Catalina package
Moderate
CVE-2003-0866
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 29, 2022
Jetty HTTP Server Denial of Service vulnerability
Moderate
CVE-2004-2381
was published
for
org.mortbay.jetty:jetty
(Maven)
Apr 29, 2022
Apache James Denial of Service
Moderate
CVE-2004-2650
was published
for
org.apache.james:james-server
(Maven)
Apr 29, 2022
Apache Tomcat DoS Via Requests Including Null Characters
Moderate
CVE-2002-0935
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
Apache Tomcat Denial of Service via Malformed Request Headers
Moderate
CVE-2009-0033
was published
for
org.apache.tomcat:tomcat
(Maven)
May 2, 2022
Denial of Service in Apache POI
Moderate
CVE-2012-0213
was published
for
org.apache.poi:poi
(Maven)
May 4, 2022
Uncontrolled Resource Consumption in Apache Commons Compress
Moderate
CVE-2012-2098
was published
for
org.apache.commons:commons-compress
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API