Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

79 advisories

Loading
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
tynus2 Credited to tynus2
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text High
CVE-2026-59887 was published for linkify-it (npm) Jul 21, 2026
bibu123456 Credited to bibu123456 and Kayiz-PT Kayiz-PT Kayiz-PT
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth, 36degrees, jdeniau, chintan-ladani-coherent, ravali-ch15, and domcleal 36degrees 36degrees
jdeniau jdeniau chintan-ladani-coherent chintan-ladani-coherent ravali-ch15 ravali-ch15 domcleal domcleal
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) High
CVE-2026-13311 was published for shell-quote (npm) Jul 20, 2026
bibu123456 Credited to bibu123456, Kayiz-PT, and ljharb Kayiz-PT Kayiz-PT
ljharb ljharb
offset Credited to offset
offset Credited to offset
js-yaml: YAML merge-key chains can force quadratic CPU consumption High
CVE-2026-59869 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups High
CVE-2026-13149 was published for brace-expansion (npm) Jul 20, 2026
bnbdr Credited to bnbdr, ljharb, and juliangruber ljharb ljharb
juliangruber juliangruber
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields High
CVE-2026-49250 was published for @conform-to/dom (npm) Jul 2, 2026
jviide Credited to jviide
tonghuaroot Credited to tonghuaroot
AArnott Credited to AArnott
parse-server: Denial of service via exponential-time processing of deeply nested query operators High
GHSA-cgxm-vr2f-6fj8 was published for parse-server (npm) Jun 19, 2026
sajdakabir Credited to sajdakabir, mtrezza, zerotrail-ai, and immadsahin mtrezza mtrezza
zerotrail-ai zerotrail-ai immadsahin immadsahin
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service High
CVE-2026-53539 was published for python-multipart (pip) Jun 15, 2026
maxisbey Credited to maxisbey
Spring Framework Algorithmic Denial of Service via SpEL Expressions High
CVE-2026-41850 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Absinthe: Quadratic fragment-name uniqueness check High
CVE-2026-43967 was published for absinthe (Erlang) May 14, 2026
PJUllrich Credited to PJUllrich and cschiewek cschiewek cschiewek
tomasilluminati Credited to tomasilluminati
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments High
GHSA-fc86-6rv6-2jpm was published for webonyx/graphql-php (Composer) May 4, 2026
d0cs1s-bzhunt Credited to d0cs1s-bzhunt and BZHunt BZHunt BZHunt
Pretext: Algorithmic Complexity (DoS) in the text analysis phase High
GHSA-5478-66c3-rhxr was published for @chenglou/pretext (npm) Apr 8, 2026
NapongiZero Credited to NapongiZero
ProTip! Advisories are also available from the GraphQL API