GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,035
Maven
5,000+
npm
3,732
NuGet
662
pip
3,413
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
104 advisories
Filter by severity
An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree:...
Moderate
Unreviewed
CVE-2018-11254
was published
May 13, 2022
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a...
Moderate
Unreviewed
CVE-2018-11597
was published
May 13, 2022
In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image...
Moderate
Unreviewed
CVE-2018-5772
was published
May 13, 2022
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary...
Moderate
Unreviewed
CVE-2018-5759
was published
May 13, 2022
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30....
Moderate
Unreviewed
CVE-2018-9996
was published
May 13, 2022
pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream...
Moderate
Unreviewed
CVE-2018-6544
was published
May 13, 2022
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c,...
Moderate
Unreviewed
CVE-2020-12825
was published
May 24, 2022
GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust...
Moderate
Unreviewed
CVE-2021-46195
was published
Jan 15, 2022
The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently,...
Moderate
Unreviewed
CVE-2022-23889
was published
Jan 29, 2022
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting...
Moderate
Unreviewed
CVE-2022-37034
was published
Feb 2, 2023
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as...
Moderate
Unreviewed
CVE-2019-17450
was published
May 24, 2022
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
Moderate
Unreviewed
CVE-2019-16163
was published
May 24, 2022
LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass:...
Moderate
Unreviewed
CVE-2018-20822
was published
May 24, 2022
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service ...
Moderate
Unreviewed
CVE-2018-20821
was published
May 24, 2022
An issue was discovered in the Linux kernel before 5.8. lib/nlattr.c allows attackers to cause a...
Moderate
Unreviewed
CVE-2020-36691
was published
Mar 24, 2023
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial...
Moderate
Unreviewed
CVE-2021-3997
was published
Aug 24, 2022
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Moderate
Unreviewed
CVE-2022-1771
was published
May 19, 2022
GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite...
Moderate
Unreviewed
CVE-2022-47662
was published
Jan 5, 2023
Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.
Moderate
Unreviewed
CVE-2022-3222
was published
Sep 16, 2022
Uncontrolled recursion leads to abort in deserialization
Moderate
GHSA-39vw-qp34-rmwf
was published
for
serde_yaml
(Rust)
Aug 25, 2021
Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec
Moderate
CVE-2021-36154
was published
for
github.com/grpc/grpc-swift
(Swift)
May 22, 2023
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively...
Moderate
Unreviewed
CVE-2022-31628
was published
Sep 29, 2022
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild...
Moderate
Unreviewed
CVE-2018-18020
was published
May 13, 2022
A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union...
Moderate
Unreviewed
CVE-2019-20395
was published
May 24, 2022
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for...
Moderate
Unreviewed
CVE-2019-18854
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API