GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
177 advisories
Filter by severity
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email...
Moderate
Unreviewed
CVE-2024-58379
was published
Aug 31, 2026
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression...
Moderate
Unreviewed
CVE-2026-77082
was published
Aug 20, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Moderate
CVE-2026-66062
was published
for
@sveltejs/kit
(npm)
Aug 7, 2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Moderate
CVE-2026-70493
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Moderate
CVE-2026-70489
was published
for
open-webui
(pip)
Aug 4, 2026
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
Moderate
CVE-2026-69207
was published
for
hono
(npm)
Aug 3, 2026
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1...
Moderate
Unreviewed
CVE-2026-23985
was published
Jul 30, 2026
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Moderate
CVE-2026-59220
was published
for
open-webui
(pip)
Jul 24, 2026
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule...
Moderate
Unreviewed
CVE-2026-16270
was published
Jul 22, 2026
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the...
Moderate
Unreviewed
CVE-2026-62237
was published
Jul 17, 2026
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the...
Moderate
Unreviewed
CVE-2026-6850
was published
Jul 13, 2026
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This...
Moderate
Unreviewed
CVE-2026-15154
was published
Jul 8, 2026
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
Moderate
GHSA-x4hg-hfwf-p9mw
was published
for
@asymmetric-effort/nogginlessdom
(npm)
Jul 2, 2026
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS)...
Moderate
Unreviewed
CVE-2025-71379
was published
Jun 20, 2026
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Moderate
GHSA-g75f-g53v-794x
was published
for
bleach
(pip)
Jun 16, 2026
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
Moderate
CVE-2026-48125
was published
for
ua-parser-js
(npm)
Jun 15, 2026
Claw Orchestrator has inefficient regular expression complexity via validateRegex()
Moderate
CVE-2026-10291
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 2, 2026
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
Moderate
CVE-2026-45409
was published
for
idna
(pip)
May 19, 2026
Svelte: ReDoS in `<svelte:element>` Tag Validation
Moderate
CVE-2026-42567
was published
for
svelte
(npm)
May 14, 2026
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Moderate
CVE-2026-44796
was published
for
nautobot
(pip)
May 13, 2026
ShellHub has crash-DoS via field injection in filter and sort-by parameters
Moderate
CVE-2026-44425
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verification
Moderate
CVE-2026-35041
was published
for
fast-jwt
(npm)
Apr 9, 2026
skilleton has improper input handling in repository/path processing
Moderate
GHSA-5g3j-89fr-r2vp
was published
for
skilleton
(npm)
Apr 8, 2026
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
Moderate
CVE-2026-34939
was published
for
praisonai
(pip)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API