How GitHub uses CodeQL to secure GitHub

GitHub's Product Security Engineering team writes code and implements tools that help secure the code that powers GitHub. We use GitHub Advanced Security (GHAS) to discover, track, and remediate ...

Continue Reading
Security Bulletin: Vulnerability in GraphQL Java affects IBM watsonx Assistant for IBM Cloud Pak for Data

Summary Potential vulnerability in GraphQL Java has been identified that affects IBM watsonx Assistant for IBM Cloud Pak for Data. The vulnerability have been addressed. Refer to details for additiona ...

Continue Reading
Security Bulletin: The IBM® Engineering Lifecycle Engineering products using IBM WebSphere Application Server Liberty is vulnerable to a denial of service due to GraphQL Java

Summary There is a vulnerability in the GraphQL Java library used by IBM WebSphere Application Server Liberty with the mpGraphQL-1.0 or mpGraphQL-2.0 feature enabled. Following IBM® Engineering Lifec ...

Continue Reading
Malicious code in solana-graphql-playground (npm)

-= Per source details. Do not edit below this line.=- Source: ghsa-malware (293a02fa1726046ea481def165e8c209dc7e6e1b108bc997d12977ecd4e613f7) Any computer that has this package installed or running sh ...

Continue Reading
Security Bulletin: There is a Denial of Service vulnerability in IBM WebSphere Liberty that is shipped with IBM TXSeries for Multiplatforms (CVE-2024-40094).

Summary There is a Denial of Service vulnerability in IBM WebSphere Liberty that is shipped with IBM TXSeries for Multiplatforms (CVE-2024-40094). An update to IBM TXSeries for Multiplatforms has been ...

Continue Reading
Security Bulletin: There is a Denial of Service vulnerability in IBM WebSphere Liberty that is shipped with IBM CICS TX Standard (CVE-2024-40094).

Summary There is a Denial of Service vulnerability in IBM WebSphere Liberty that is shipped with IBM CICS TX Standard (CVE-2024-40094). An update to IBM CICS TX Standard has been released to address t ...

Continue Reading
Security Bulletin: There is a Denial of Service vulnerability in IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced (CVE-2024-40094).

Summary There is a Denial of Service vulnerability in IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced (CVE-2024-40094). An update to IBM CICS TX Advanced has been released to address t ...

Continue Reading
(RHSA-2025:0664) Moderate: Release of OpenShift Serverless Logic 1.35.0 security update & enhancements

This release includes security, bug fixes, and enhancements. Security Fix(es): com.graphql-java/graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java (CVE-2024-40094) ...

Continue Reading

Back to Main

Subscribe for the latest news: