GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
262 advisories
Filter by severity
Hugging Face Transformers library has Regular Expression Denial of Service
Moderate
CVE-2025-6051
was published
for
transformers
(pip)
Sep 14, 2025
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Moderate
CVE-2025-6638
was published
for
transformers
(pip)
Sep 12, 2025
Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity
High
CVE-2025-58451
was published
for
cattown
(npm)
Sep 9, 2025
Inefficient Regular Expression Complexity in Liferay Portal
High
CVE-2022-42124
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
nodemailer ReDoS when trying to send a specially crafted email
Moderate
GHSA-9h6g-pr28-7cqp
was published
for
nodemailer
(npm)
Jan 31, 2024
useragent Regular Expression Denial of Service vulnerability
Moderate
CVE-2020-26311
was published
for
useragent
(npm)
Oct 26, 2024
domain-suffix RegEx Denial of Service
High
CVE-2024-25354
was published
for
domain-suffix
(npm)
Mar 28, 2024
parse-uri Regular expression Denial of Service (ReDoS)
Moderate
CVE-2024-36751
was published
for
parse-uri
(npm)
Jan 16, 2025
Regular expression denial of service in apache tika
Moderate
CVE-2022-30126
was published
for
org.apache.tika:tika-core
(Maven)
May 17, 2022
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54364
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54363
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Moderate
CVE-2025-43764
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Aug 23, 2025
Regular Expression Denial of Service (ReDoS) in lodash
Moderate
CVE-2020-28500
was published
for
lodash
(RubyGems)
Jan 6, 2022
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Moderate
CVE-2025-3933
was published
for
transformers
(pip)
Jul 11, 2025
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-26042
was published
for
uptime-kuma
(npm)
Mar 31, 2025
Duplicate Advisory: Uptime Kuma ReDoS vulnerability
Moderate
GHSA-3rw8-4xrq-3f7p
was published
for
uptime-kuma
(npm)
Mar 17, 2025
•
withdrawn
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-5197
was published
for
transformers
(pip)
Aug 6, 2025
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Moderate
CVE-2025-3262
was published
for
transformers
(pip)
Jul 7, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-1194
was published
for
transformers
(pip)
Apr 29, 2025
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
High
CVE-2025-54796
was published
for
copyparty
(pip)
Aug 4, 2025
Withdrawn Advisory: ReDoS in py library when used with subversion
High
CVE-2022-42969
was published
for
py
(pip)
Oct 16, 2022
•
withdrawn
@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser
Low
GHSA-xffm-g5w8-qvg7
was published
for
@eslint/plugin-kit
(npm)
Jul 18, 2025
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
CVE-2025-6998
was published
for
calibreweb
(pip)
Jul 24, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
ProTip!
Advisories are also available from the
GraphQL API