Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

115 advisories

Loading
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
js-yaml: Exponential parsing time in flow collections leads to denial of service High
GHSA-pm4m-ph32-ghv5 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
tynus2 Credited to tynus2
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text High
CVE-2026-59887 was published for linkify-it (npm) Jul 21, 2026
bibu123456 Credited to bibu123456 and Kayiz-PT Kayiz-PT Kayiz-PT
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) High
CVE-2026-13311 was published for shell-quote (npm) Jul 20, 2026
bibu123456 Credited to bibu123456, Kayiz-PT, and ljharb Kayiz-PT Kayiz-PT
ljharb ljharb
offset Credited to offset
offset Credited to offset
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: YAML merge-key chains can force quadratic CPU consumption High
CVE-2026-59869 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups High
CVE-2026-13149 was published for brace-expansion (npm) Jul 20, 2026
bnbdr Credited to bnbdr, ljharb, and juliangruber ljharb ljharb
juliangruber juliangruber
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields High
CVE-2026-49250 was published for @conform-to/dom (npm) Jul 2, 2026
jviide Credited to jviide
tonghuaroot Credited to tonghuaroot
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings Moderate
CVE-2026-48516 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
ProTip! Advisories are also available from the GraphQL API