GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
34 advisories
Filter by severity
Duplicate Advisory: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses (CWE-776)
High
GHSA-jx89-3qg8-p2mr
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
High
CVE-2026-73569
was published
for
fast-xml-parser
(npm)
Jul 21, 2026
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
High
CVE-2026-54077
was published
for
com.arcadedb:arcadedb-engine
(Maven)
Jul 16, 2026
Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser
High
GHSA-p5wc-9w9r-m232
was published
for
ultimate-sitemap-parser
(pip)
Jun 19, 2026
Routinator crashes when encountering maliciously crafted RRDP XML files
High
CVE-2026-49235
was published
for
routinator
(Rust)
Jun 8, 2026
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
High
CVE-2026-44020
was published
for
docling
(pip)
Jun 3, 2026
Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks
High
CVE-2026-31248
was published
for
docling
(pip)
May 11, 2026
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
High
CVE-2026-33036
was published
for
fast-xml-parser
(npm)
Mar 17, 2026
SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)
High
CVE-2026-29074
was published
for
svgo
(npm)
Mar 4, 2026
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
High
CVE-2026-26278
was published
for
fast-xml-parser
(npm)
Feb 17, 2026
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
High
CVE-2025-3225
was published
for
llama-index-readers-papers
(pip)
Jul 7, 2025
REXML denial of service vulnerability
High
CVE-2024-43398
was published
for
rexml
(RubyGems)
Aug 22, 2024
Zendframework Denial of Service vector via XEE injection
High
GHSA-2jx7-xg83-j2m7
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
ebookmeta XML External Entity vulnerability
High
CVE-2024-36827
was published
for
ebookmeta
(pip)
Jun 7, 2024
ebookmeta XML External Entity vulnerability
High
CVE-2024-37388
was published
for
ebookmeta
(pip)
Jun 7, 2024
symfony/validator XML Entity Expansion vulnerability
High
GHSA-4vf2-qfg3-7598
was published
for
symfony/validator
(Composer)
May 30, 2024
symfony/translation XML Entity Expansion vulnerability
High
GHSA-f75p-x5vm-83qp
was published
for
symfony/translation
(Composer)
May 30, 2024
Symfony XML Entity Expansion security vulnerability
High
GHSA-q2gc-gg3x-7942
was published
for
symfony/symfony
(Composer)
May 30, 2024
Apache Tiles: Unvalidated input may lead to path traversal and XXE
High
CVE-2023-49735
was published
for
org.apache.struts:struts-tiles
(Maven)
Dec 1, 2023
kaml has potential denial of service while parsing input with anchors and aliases
High
CVE-2023-28118
was published
for
com.charleskorn.kaml:kaml
(Maven)
Mar 20, 2023
Kubernetes apimachinery packages vulnerable to unbounded recursion in JSON or YAML parsing
High
GHSA-74fp-r6jw-h4mp
was published
for
k8s.io/apimachinery
(Go)
Feb 8, 2023
Uncontrolled Resource Consumption in snakeyaml
High
CVE-2022-25857
was published
for
org.yaml:snakeyaml
(Maven)
Aug 31, 2022
untangle vulnerable to XML Entity Expansion
High
CVE-2022-33977
was published
for
untangle
(pip)
Aug 6, 2022
Apache Solr vulnerable to XML Bomb
High
CVE-2019-12401
was published
for
org.apache.solr:solr-core
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Code Coverage API Plugin
High
CVE-2020-2172
was published
for
io.jenkins.plugins:code-coverage-api
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API