GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
465 advisories
Filter by severity
Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in...
Unknown
Unreviewed
CVE-2026-81928
was published
Sep 2, 2026
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to...
High
Unreviewed
CVE-2026-52130
was published
Sep 1, 2026
Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with...
Moderate
Unreviewed
CVE-2026-82797
was published
Aug 31, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
An attacker that has valid credentials can send crafted compressed data that causes the affected...
Moderate
Unreviewed
CVE-2026-73209
was published
Aug 28, 2026
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct...
Moderate
Unreviewed
CVE-2026-81724
was published
Aug 27, 2026
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
High
Unreviewed
CVE-2026-47851
was published
Aug 27, 2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled...
Moderate
Unreviewed
CVE-2026-16781
was published
Aug 24, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
High
CVE-2026-54623
was published
for
django-cms
(pip)
Aug 24, 2026
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
High
GHSA-892m-gcq8-2468
was published
for
justhtml
(pip)
Aug 23, 2026
•
withdrawn
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder...
High
Unreviewed
CVE-2026-66393
was published
Aug 22, 2026
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of...
High
Unreviewed
CVE-2026-17121
was published
Aug 21, 2026
In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations...
Moderate
Unreviewed
CVE-2026-16440
was published
Aug 19, 2026
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
High
CVE-2026-69220
was published
for
com.rabbitmq:amqp-client
(Maven)
Aug 18, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
High
CVE-2026-53752
was published
for
org.docx4j:docx4j-core
(Maven)
Aug 17, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs
High
CVE-2026-40345
was published
for
deepmerge-ts
(npm)
Aug 17, 2026
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the...
High
Unreviewed
CVE-2026-74794
was published
Aug 16, 2026
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent...
High
Unreviewed
CVE-2026-74795
was published
Aug 16, 2026
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in...
High
Unreviewed
CVE-2026-74792
was published
Aug 16, 2026
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that...
High
Unreviewed
CVE-2026-74783
was published
Aug 16, 2026
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json...
High
Unreviewed
CVE-2026-74787
was published
Aug 16, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
High
Unreviewed
CVE-2026-17177
was published
Aug 14, 2026
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request...
Moderate
Unreviewed
CVE-2026-72686
was published
Aug 13, 2026
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the...
Moderate
Unreviewed
CVE-2026-72683
was published
Aug 13, 2026
ProTip!
Advisories are also available from the
GraphQL API