GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
115 advisories
Filter by severity
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When...
High
Unreviewed
CVE-2026-67216
was published
Jul 29, 2026
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when...
Low
Unreviewed
CVE-2026-6879
was published
Jul 28, 2026
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling...
High
Unreviewed
CVE-2026-55968
was published
Jul 27, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
GHSA-gm3r-q2wp-hw87
was published
for
shescape
(npm)
Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
GHSA-pm4m-ph32-ghv5
was published
for
js-yaml
(npm)
Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
Certain query operations involving deeply nested $jsonSchema constructs can trigger...
High
Unreviewed
CVE-2026-13064
was published
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
High
CVE-2026-59887
was published
for
linkify-it
(npm)
Jul 21, 2026
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
High
CVE-2026-13311
was published
for
shell-quote
(npm)
Jul 20, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
Moderate
CVE-2026-59870
was published
for
js-yaml
(npm)
Jul 20, 2026
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
High
CVE-2026-13149
was published
for
brace-expansion
(npm)
Jul 20, 2026
Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob...
High
Unreviewed
CVE-2026-59094
was published
Jul 2, 2026
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
High
CVE-2026-49250
was published
for
@conform-to/dom
(npm)
Jul 2, 2026
fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the -...
Moderate
Unreviewed
CVE-2026-53433
was published
Jun 30, 2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
Moderate
CVE-2026-48516
was published
for
MessagePack
(NuGet)
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API