Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

472 advisories

Loading
toml-node: Uncontrolled Recursion High
CVE-2026-77465 was published for toml (npm) Sep 3, 2026
seok-hee97 Credited to seok-hee97
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown High
CVE-2026-76098 was published for mistune (pip) Sep 2, 2026
wan1yan Credited to wan1yan
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) High
CVE-2026-54623 was published for django-cms (pip) Aug 24, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML High
GHSA-892m-gcq8-2468 was published for justhtml (pip) Aug 23, 2026 withdrawn
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS High
CVE-2026-69220 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs High
CVE-2026-40345 was published for deepmerge-ts (npm) Aug 17, 2026
Jvr2022 Credited to Jvr2022
ProTip! Advisories are also available from the GraphQL API