GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
472 advisories
Filter by severity
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM...
Moderate
Unreviewed
CVE-2026-17440
was published
Sep 4, 2026
A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an...
Moderate
Unreviewed
CVE-2026-14255
was published
Sep 2, 2026
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
High
CVE-2026-76098
was published
for
mistune
(pip)
Sep 2, 2026
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
Moderate
CVE-2026-12876
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
Moderate
CVE-2026-81724
was published
for
nltk
(pip)
Sep 2, 2026
Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in...
High
Unreviewed
CVE-2026-81928
was published
Sep 2, 2026
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers...
High
Unreviewed
CVE-2026-52132
was published
Sep 1, 2026
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to...
High
Unreviewed
CVE-2026-52130
was published
Sep 1, 2026
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with...
Moderate
Unreviewed
CVE-2026-82797
was published
Aug 31, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
An attacker that has valid credentials can send crafted compressed data that causes the affected...
Moderate
Unreviewed
CVE-2026-73209
was published
Aug 28, 2026
Duplicate Advisory: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
Moderate
GHSA-pf76-q698-37v8
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
High
Unreviewed
CVE-2026-47851
was published
Aug 27, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled...
Moderate
Unreviewed
CVE-2026-16781
was published
Aug 24, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
High
CVE-2026-54623
was published
for
django-cms
(pip)
Aug 24, 2026
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
High
GHSA-892m-gcq8-2468
was published
for
justhtml
(pip)
Aug 23, 2026
•
withdrawn
Duplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
High
GHSA-cv2g-m8rr-888c
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of...
High
Unreviewed
CVE-2026-17121
was published
Aug 21, 2026
In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations...
Moderate
Unreviewed
CVE-2026-16440
was published
Aug 19, 2026
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
High
CVE-2026-69220
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs
High
CVE-2026-40345
was published
for
deepmerge-ts
(npm)
Aug 17, 2026
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the...
High
Unreviewed
CVE-2026-74794
was published
Aug 16, 2026
ProTip!
Advisories are also available from the
GraphQL API