GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
821 advisories
Filter by severity
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
High
CVE-2026-4598
was published
for
jsrsasign
(npm)
Mar 23, 2026
Denial of service via non-terminating SYLT frame parsing loop in tinytag
Moderate
CVE-2026-32889
was published
for
tinytag
(pip)
Mar 19, 2026
UltraJSON has an integer overflow handling large indent leads to buffer overflow or infinite loop
High
CVE-2026-32875
was published
for
ujson
(pip)
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: fix infinite loop...
Moderate
Unreviewed
CVE-2025-71265
was published
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: fix infinite loop...
Moderate
Unreviewed
CVE-2025-71267
was published
Mar 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: check return...
Moderate
Unreviewed
CVE-2025-71266
was published
Mar 18, 2026
music-metadata has an infinite loop vulnerability in ASF parser
High
CVE-2026-32256
was published
for
music-metadata
(npm)
Mar 17, 2026
Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
High
CVE-2026-33013
was published
for
io.micronaut:micronaut-json-core
(Maven)
Mar 17, 2026
Denial of Service in pyasn1 via Unbounded Recursion
High
CVE-2026-30922
was published
for
pyasn1
(pip)
Mar 17, 2026
Loop with Unreachable Exit Condition ('Infinite Loop') in ewe
High
CVE-2026-32873
was published
for
ewe
(Erlang)
Mar 16, 2026
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Moderate
Unreviewed
CVE-2026-32777
was published
Mar 16, 2026
A flaw was identified in the RAR5 archive decompression logic of the libarchive library,...
High
Unreviewed
CVE-2026-4111
was published
Mar 13, 2026
file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header
Moderate
CVE-2026-31808
was published
for
file-type
(npm)
Mar 10, 2026
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a...
Moderate
Unreviewed
CVE-2025-69647
was published
Mar 9, 2026
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a...
Moderate
Unreviewed
CVE-2025-69648
was published
Mar 9, 2026
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does...
High
Unreviewed
CVE-2026-2219
was published
Mar 7, 2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could...
Moderate
Unreviewed
CVE-2026-20054
was published
Mar 4, 2026
pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
Low
CVE-2026-27628
was published
for
pypdf
(pip)
Feb 25, 2026
ImageMagick has a possible infinite loop in its JPEG encoder when using `jpeg:extent`
Moderate
CVE-2026-26283
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafted profile
Moderate
CVE-2026-26066
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 24, 2026
bn.js affected by an infinite loop
Moderate
CVE-2026-2739
was published
for
bn.js
(npm)
Feb 20, 2026
pypdf has a possible infinite loop when processing TreeObject
Moderate
CVE-2026-27024
was published
for
pypdf
(pip)
Feb 18, 2026
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix infinite loop...
Moderate
Unreviewed
CVE-2026-23220
was published
Feb 18, 2026
Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0:...
Moderate
Unreviewed
CVE-2025-27560
was published
Feb 10, 2026
Sandbox escape via infinite recursion and error objects
Moderate
CVE-2026-25533
was published
for
@enclave-vm/core
(npm)
Feb 5, 2026
ProTip!
Advisories are also available from the
GraphQL API