GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
35 advisories
Filter by severity
SwiftNIO SSL arbitrary code execution vulnerability
Critical
CVE-2019-8849
was published
for
github.com/apple/swift-nio-ssl
(Swift)
May 24, 2022
Vapor vulnerable to denial of service in HTTP Range Request of FileMiddleware
High
CVE-2022-31005
was published
for
github.com/vapor/vapor
(Swift)
Jun 7, 2023
Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder
High
CVE-2022-1642
was published
for
github.com/apple/swift-corelibs-foundation
(Swift)
Jun 7, 2023
Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec
Moderate
CVE-2021-36154
was published
for
github.com/grpc/grpc-swift
(Swift)
May 22, 2023
Async HTTP Client has CRLF Injection vulnerability in HTTP request headers
High
CVE-2023-0040
was published
for
github.com/swift-server/async-http-client
(Swift)
Jun 7, 2023
SwiftNIO vulnerable to Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Moderate
CVE-2022-3215
was published
for
github.com/apple/swift-nio
(Swift)
Jun 7, 2023
SwiftNIO Extras vulnerable to improper detection of complete HTTP body decompression
High
CVE-2022-3252
was published
for
github.com/apple/swift-nio-extras
(Swift)
Jun 7, 2023
Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec
High
CVE-2021-36153
was published
for
github.com/grpc/grpc-swift
(Swift)
Jun 9, 2023
LeafKit allows XSS with untrusted user input
Moderate
CVE-2021-37634
was published
for
github.com/vapor/leaf-kit
(Swift)
Jun 9, 2023
Untrusted data fed into `Data.init(base32Encoded:)` can result in exposing server memory and/or crash
Moderate
CVE-2021-32742
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
Arbitrary file read using percent-encoded relative paths in FileMiddleware
Moderate
CVE-2020-15230
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
Uncontrolled Resource Consumption in LengthPrefixedMessageReader
High
CVE-2021-36155
was published
for
github.com/grpc/grpc-swift
(Swift)
Jun 9, 2023
Vapor's Metrics integration could cause a system drain
Moderate
CVE-2021-21328
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
SwiftNIO vulnerable to HTTP request smuggling using malformed Transfer-Encoding header
Critical
GHSA-mgc4-wqv7-4pxm
was published
for
github.com/apple/swift-nio
(Swift)
May 18, 2023
Duplicate advisory: swift-nio-http2 vulnerable to denial of service via ALTSVC or ORIGIN frames
High
GHSA-gpgx-whwh-r297
was published
for
github.com/apple/swift-nio-http2
(Swift)
Feb 11, 2022
•
withdrawn
swift-nio-http2 vulnerable to denial of service via ALTSVC or ORIGIN frames
High
CVE-2022-24668
was published
for
github.com/apple/swift-nio-http2
(Swift)
May 18, 2023
Duplicate advisory: swift-nio-http2 vulnerable to denial of service via mishandled HPACK variable length integer encoding
High
GHSA-wfvq-p7qf-vv64
was published
for
github.com/apple/swift-nio-http2
(Swift)
Feb 11, 2022
•
withdrawn
swift-nio-http2 vulnerable to denial of service via mishandled HPACK variable length integer encoding
High
CVE-2022-24667
was published
for
github.com/apple/swift-nio-http2
(Swift)
May 18, 2023
Duplicate advisory: swift-nio-http2 vulnerable to denial of service via invalid HTTP/2 HEADERS frame length
High
GHSA-pv7r-9vjg-g3f9
was published
for
github.com/apple/swift-nio-http2
(Swift)
Feb 11, 2022
•
withdrawn
Vapor vulnerable to denial of service in URLEncodedFormDecoder
High
CVE-2022-31019
was published
for
github.com/vapor/vapor
(Swift)
Jun 7, 2023
swift-nio-http2 vulnerable to denial of service via invalid HTTP/2 HEADERS frame length
High
CVE-2022-24666
was published
for
github.com/apple/swift-nio-http2
(Swift)
May 18, 2023
zstd vulnerable to buffer overrun
High
CVE-2022-4899
was published
for
github.com/facebook/zstd
(pip)
Mar 31, 2023
PostgresNIO processes unencrypted bytes from man-in-the-middle
Low
CVE-2023-31136
was published
for
github.com/vapor/postgres-nio
(Swift)
May 10, 2023
Vapor contains an integer overflow in URI leading to potential host spoofing
Moderate
CVE-2024-21631
was published
for
github.com/vapor/vapor
(Swift)
Jan 3, 2024
Vapor's incorrect request error handling triggers server crash
Moderate
CVE-2023-44386
was published
for
github.com/vapor/vapor
(Swift)
Oct 5, 2023
ProTip!
Advisories are also available from the
GraphQL API