GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
79 advisories
Filter by severity
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
High
CVE-2026-59885
was published
for
pyasn1
(pip)
Jul 21, 2026
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
High
CVE-2026-59887
was published
for
linkify-it
(npm)
Jul 21, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
High
CVE-2026-13311
was published
for
shell-quote
(npm)
Jul 20, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
High
CVE-2026-13149
was published
for
brace-expansion
(npm)
Jul 20, 2026
Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob...
High
Unreviewed
CVE-2026-59094
was published
Jul 2, 2026
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
High
CVE-2026-49250
was published
for
@conform-to/dom
(npm)
Jul 2, 2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
High
CVE-2026-48502
was published
for
MessagePack
(NuGet)
Jun 25, 2026
parse-server: Denial of service via exponential-time processing of deeply nested query operators
High
GHSA-cgxm-vr2f-6fj8
was published
for
parse-server
(npm)
Jun 19, 2026
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
High
CVE-2026-53539
was published
for
python-multipart
(pip)
Jun 15, 2026
Spring Framework Algorithmic Denial of Service via SpEL Expressions
High
CVE-2026-41850
was published
for
org.springframework:spring-expression
(Maven)
Jun 9, 2026
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL...
High
Unreviewed
CVE-2026-8889
was published
Jun 3, 2026
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume...
High
Unreviewed
CVE-2026-42504
was published
Jun 3, 2026
IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop...
High
Unreviewed
CVE-2026-48959
was published
May 27, 2026
Absinthe: Quadratic fragment-name uniqueness check
High
CVE-2026-43967
was published
for
absinthe
(Erlang)
May 14, 2026
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
High
CVE-2026-42304
was published
for
Twisted
(pip)
May 5, 2026
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments
High
GHSA-fc86-6rv6-2jpm
was published
for
webonyx/graphql-php
(Composer)
May 4, 2026
Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
High
Unreviewed
CVE-2025-67841
was published
Apr 15, 2026
Pretext: Algorithmic Complexity (DoS) in the text analysis phase
High
GHSA-5478-66c3-rhxr
was published
for
@chenglou/pretext
(npm)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API