GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
HTTP/2 rapid reset can cause excessive work in net/http
High
CVE-2023-39325
was published
for
golang.org/x/net
(Go)
Oct 11, 2023
HTTP/2 Stream Cancellation Attack
Moderate
CVE-2023-44487
was published
for
com.typesafe.akka:akka-http-core
(Go)
Oct 10, 2023
github.com/nghttp2/nghttp2 has HTTP/2 Rapid Reset
High
GHSA-vx74-f528-fxqg
was published
for
github.com/nghttp2/nghttp2
(Go)
Oct 10, 2023
Mattermost Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2023-5196
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Sep 29, 2023
Argo CD repo-server Denial of Service vulnerability
Moderate
CVE-2023-40584
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 11, 2023
Go-Ethereum vulnerable to denial of service via malicious p2p message
High
CVE-2023-40591
was published
for
github.com/ethereum/go-ethereum
(Go)
Sep 6, 2023
libp2p nodes vulnerable to OOM attack
High
CVE-2023-40583
was published
for
github.com/libp2p/go-libp2p
(Go)
Aug 24, 2023
Denial of service from large image
Low
CVE-2023-37900
was published
for
github.com/crossplane/crossplane
(Go)
Jul 28, 2023
goproxy Denial of Service vulnerability
High
CVE-2023-37788
was published
for
github.com/elazarl/goproxy
(Go)
Jul 18, 2023
avro vulnerable to denial of service via attacker-controlled parameter
High
CVE-2023-37475
was published
for
github.com/hamba/avro
(Go)
Jul 17, 2023
mx-chain-go's relayed transactions always increment nonce
High
CVE-2023-34458
was published
for
github.com/multiversx/mx-chain-go
(Go)
Jul 13, 2023
Coraza has potential denial of service vulnerability
High
CVE-2023-40586
was published
for
github.com/corazawaf/coraza/v2
(Go)
Jun 26, 2023
Notation's default `maxSignatureAttempts` in `notation verify` enables an endless data attack
Moderate
CVE-2023-33958
was published
for
github.com/notaryproject/notation
(Go)
Jun 6, 2023
Notation vulnerable to denial of service from high number of artifact signatures
Moderate
CVE-2023-33957
was published
for
github.com/notaryproject/notation
(Go)
Jun 6, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
Moderate
GHSA-qvqg-6rp8-4p9h
was published
for
github.com/ipfs/kubo
(Go)
May 11, 2023
github.com/ipfs/go-bitswap vulnerable to DOS unbounded persistent memory leak
High
GHSA-q3j6-22wf-3jh9
was published
for
github.com/ipfs/go-bitswap
(Go)
May 11, 2023
Boxo bitswap/server: DOS unbounded persistent memory leak
High
CVE-2023-25568
was published
for
github.com/ipfs/go-libipfs
(Go)
May 11, 2023
Traefik HTTP header parsing could cause a denial of service
High
CVE-2023-29013
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 11, 2023
Stud42 vulnerable to denial of service
High
GHSA-3hwm-922r-47hw
was published
for
atomys.codes/stud42
(Go)
Mar 31, 2023
fieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtime
Moderate
CVE-2023-27483
was published
for
github.com/crossplane/crossplane-runtime
(Go)
Mar 13, 2023
Crossplane-runtime contains Improper Input Validation via Compositions
Moderate
CVE-2023-27484
was published
for
github.com/crossplane/crossplane
(Go)
Mar 10, 2023
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-41723
was published
for
golang.org/x/net
(Go)
Feb 17, 2023
Uncontrolled Resource Consumption in golang.org/x/image
Moderate
CVE-2022-41727
was published
for
golang.org/x/image
(Go)
Feb 17, 2023
Uncontrolled Resource Consumption in Hashicorp Nomad
Moderate
CVE-2023-0821
was published
for
github.com/hashicorp/nomad
(Go)
Feb 17, 2023
OCI image importer memory exhaustion in github.com/containerd/containerd
Moderate
CVE-2023-25153
was published
for
github.com/containerd/containerd
(Go)
Feb 16, 2023
ProTip!
Advisories are also available from the
GraphQL API