GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
207 advisories
Filter by severity
Apache CXF: Denial of Service vulnerability with temporary files
High
CVE-2025-23184
was published
for
org.apache.cxf:cxf-core
(Maven)
Jan 21, 2025
Hash collision in typelevel jawn
Moderate
CVE-2022-21653
was published
for
org.typelevel:jawn-parser_0.25
(Maven)
Jan 6, 2022
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
Low
CVE-2025-66453
was published
for
org.mozilla:rhino
(Maven)
Dec 3, 2025
Liferay Portal Vulnerable to DoS via Crafted Headless API Request
High
CVE-2025-62260
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side
Moderate
CVE-2025-58369
was published
for
co.fs2:fs2-io_0.26
(Maven)
Sep 5, 2025
Apereo CAS has inefficient regular expression complexity
Moderate
CVE-2025-3985
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
High
CVE-2025-5115
was published
for
org.eclipse.jetty.http2:http2-common
(Maven)
Aug 20, 2025
Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
Moderate
CVE-2025-48795
was published
for
org.apache.cxf:cxf-core
(Maven)
Jul 15, 2025
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
Moderate
CVE-2025-53506
was published
for
org.apache.tomcat:tomcat-coyote
(Maven)
Jul 10, 2025
jose4j denial of service via specifically crafted JWE
Moderate
CVE-2023-51775
was published
for
org.bitbucket.b_c:jose4j
(Maven)
Feb 29, 2024
Denial of Service by injecting highly recursive collections or maps in XStream
High
CVE-2021-43859
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Feb 1, 2022
Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
Moderate
CVE-2024-8184
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 14, 2024
Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
Low
CVE-2024-6762
was published
for
org.eclipse.jetty:jetty-servlets
(Maven)
Oct 14, 2024
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Moderate
CVE-2024-54677
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Dec 17, 2024
Eclipse Jetty has a denial of service vulnerability on DosFilter
Moderate
CVE-2024-9823
was published
for
org.eclipse.jetty.ee10:jetty-ee10-servlets
(Maven)
Oct 14, 2024
Apache Tomcat - Denial of Service
High
CVE-2024-34750
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jul 3, 2024
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
Moderate
CVE-2025-12194
was published
for
org.bouncycastle:bc-fips
(Maven)
Oct 25, 2025
Keycloak TLS Client-Initiated Renegotiation Denial of Service
High
CVE-2025-11419
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Oct 27, 2025
HTTP/2 Stream Cancellation Attack
Moderate
CVE-2023-44487
was published
for
com.typesafe.akka:akka-http-core
(Go)
Oct 10, 2023
Remote code injection in Log4j
Critical
CVE-2021-44228
was published
for
com.guicedee.services:log4j-core
(Maven)
Dec 10, 2021
H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
High
CVE-2024-7768
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) and File Write
High
CVE-2024-10572
was published
for
ai.h2o:h2o-ext-xgboost
(Maven)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
High
CVE-2024-10549
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Denial of service in jackson-dataformat-toml
High
CVE-2023-3894
was published
for
com.fasterxml.jackson.dataformat:jackson-dataformat-toml
(Maven)
Aug 8, 2023
Elasticsearch Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2024-52979
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 1, 2025
ProTip!
Advisories are also available from the
GraphQL API