Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

465 advisories

Loading
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct... Moderate Unreviewed
CVE-2026-81724 was published Aug 27, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) High
CVE-2026-54623 was published for django-cms (pip) Aug 24, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML High
GHSA-892m-gcq8-2468 was published for justhtml (pip) Aug 23, 2026 withdrawn
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS High
CVE-2026-69220 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs High
CVE-2026-40345 was published for deepmerge-ts (npm) Aug 17, 2026
Jvr2022 Credited to Jvr2022
ProTip! Advisories are also available from the GraphQL API