GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
37 advisories
Filter by severity
Buffer Overflow in Apache Mina SSHD
High
CVE-2021-30129
was published
for
org.apache.sshd:sshd-core
(Maven)
Aug 2, 2021
S3 storage write is not aborted on errors leading to unbounded memory usage
High
GHSA-m6m5-pp4g-fcc8
was published
for
github.com/foxcpp/maddy
(Go)
Oct 6, 2021
Missing Release of Resource after Effective Lifetime in Apache Tomcat
High
CVE-2021-42340
was published
for
org.apache.tomcat:tomcat
(Maven)
Oct 15, 2021
Uncontrolled Resource Consumption in promhttp
High
CVE-2022-21698
was published
for
github.com/prometheus/client_golang
(Go)
Feb 16, 2022
Uncontrolled Resource Consumption in Matrix Synapse
Moderate
CVE-2022-41952
was published
for
matrix-synapse
(pip)
Apr 1, 2022
Missing Release of Resource after Effective Lifetime in Jenkins
High
CVE-2018-1999043
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
OpenStack Neutron Denial of Service vulnerability
High
CVE-2021-40797
was published
for
neutron
(pip)
May 24, 2022
golang.org/x/text/language Denial of service via crafted Accept-Language header
High
CVE-2022-32149
was published
for
golang.org/x/text
(Go)
Oct 14, 2022
Bunkum tokens cached in the AuthenticationService are susceptible to a use-after-free
Moderate
CVE-2023-45814
was published
for
Bunkum
(NuGet)
Oct 19, 2023
Traefik vulnerable to potential DDoS via ACME HTTPChallenge
Moderate
CVE-2023-47124
was published
for
github.com/traefik/traefik/v2
(Go)
Dec 5, 2023
Etcd Gateway can include itself as an endpoint resulting in resource exhaustion
High
CVE-2020-15114
was published
for
go.etcd.io/etcd
(Go)
Jan 31, 2024
Eclipse Vert.x vulnerable to a memory leak in TCP servers
Moderate
CVE-2024-1300
was published
for
io.vertx:vertx-core
(Maven)
Apr 2, 2024
Apache Answer: The link to reset the user's password will remain valid after sending a new link
Moderate
CVE-2024-41890
was published
for
github.com/apache/incubator-answer
(Go)
Aug 12, 2024
Apache Answer: The link for resetting user password is not Single-Use
Moderate
CVE-2024-41888
was published
for
github.com/apache/incubator-answer
(Go)
Aug 12, 2024
Waitress vulnerable to DoS leading to high CPU usage/resource exhaustion
High
CVE-2024-49769
was published
for
waitress
(pip)
Oct 29, 2024
aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method
Moderate
CVE-2024-52303
was published
for
aiohttp
(pip)
Nov 18, 2024
Goroutine Leak in Abacus SSE Implementation
High
CVE-2025-27421
was published
for
github.com/jasonlovesdoggo/abacus
(Go)
Mar 3, 2025
Pleezer resource exhaustion through uncollected hook script processes
Moderate
CVE-2025-32439
was published
for
pleezer
(Rust)
Apr 14, 2025
Hackney fails to properly release HTTP connections to the pool
Low
CVE-2025-3864
was published
for
hackney
(Erlang)
May 28, 2025
thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
High
CVE-2025-65947
was published
for
thread-amount
(Rust)
Nov 21, 2025
NiceGUI has Redis connection leak via tab storage causes service degradation
Moderate
CVE-2026-21874
was published
for
nicegui
(pip)
Jan 8, 2026
Hibernate Reactive Vulnerable to DoS via Connection Pool Exhaustion
Moderate
CVE-2025-14969
was published
for
org.hibernate.reactive:hibernate-reactive-core
(Maven)
Jan 26, 2026
ProTip!
Advisories are also available from the
GraphQL API