GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
799 advisories
Filter by severity
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
High
CVE-2026-59935
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible infinite loop for not terminated inline images
High
CVE-2026-59936
was published
for
pypdf
(pip)
Jul 23, 2026
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
High
CVE-2026-59933
was published
for
phpoffice/phpspreadsheet
(Composer)
Jul 23, 2026
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an...
High
Unreviewed
CVE-2026-64611
was published
Jul 23, 2026
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
High
CVE-2026-59901
was published
for
io.netty:netty-codec
(Maven)
Jul 22, 2026
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer...
High
Unreviewed
CVE-2026-64834
was published
Jul 22, 2026
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
High
Unreviewed
CVE-2026-56852
was published
Jul 21, 2026
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
High
CVE-2026-59879
was published
for
immutable
(npm)
Jul 21, 2026
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication...
Low
Unreviewed
CVE-2026-59849
was published
Jul 21, 2026
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Moderate
CVE-2026-59203
was published
for
pillow
(pip)
Jul 20, 2026
protobufjs: Denial of Service via infinite loop in .proto option parsing
Moderate
CVE-2026-59877
was published
for
protobufjs
(npm)
Jul 20, 2026
node-tar: Negative tar entry size causes infinite loop in archive replace
High
CVE-2026-59874
was published
for
tar
(npm)
Jul 20, 2026
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users...
High
Unreviewed
CVE-2025-71397
was published
Jul 18, 2026
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a...
Moderate
Unreviewed
CVE-2026-7771
was published
Jul 17, 2026
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed...
High
Unreviewed
CVE-2026-13401
was published
Jul 16, 2026
HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed...
High
Unreviewed
CVE-2026-13397
was published
Jul 16, 2026
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services ...
High
Unreviewed
CVE-2026-50647
was published
Jul 14, 2026
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services ...
Moderate
Unreviewed
CVE-2026-50324
was published
Jul 14, 2026
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an...
High
Unreviewed
CVE-2026-54119
was published
Jul 14, 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the...
Moderate
Unreviewed
CVE-2026-62642
was published
Jul 14, 2026
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
High
GHSA-xf7x-x43h-rpqh
was published
for
json-repair
(pip)
Jul 13, 2026
pypdf: Possible infinite loop when processing threads/articles in writer
Moderate
CVE-2026-54651
was published
for
pypdf
(pip)
Jul 9, 2026
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single...
Moderate
Unreviewed
CVE-2026-56289
was published
Jul 9, 2026
Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow...
Moderate
Unreviewed
CVE-2026-15163
was published
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API