GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
124 advisories
Filter by severity
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Moderate
CVE-2026-66062
was published
for
@sveltejs/kit
(npm)
Aug 7, 2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Moderate
CVE-2026-70493
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Moderate
CVE-2026-70489
was published
for
open-webui
(pip)
Aug 4, 2026
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
Moderate
CVE-2026-69207
was published
for
hono
(npm)
Aug 3, 2026
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Moderate
CVE-2026-59220
was published
for
open-webui
(pip)
Jul 24, 2026
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
Moderate
GHSA-x4hg-hfwf-p9mw
was published
for
@asymmetric-effort/nogginlessdom
(npm)
Jul 2, 2026
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Moderate
GHSA-g75f-g53v-794x
was published
for
bleach
(pip)
Jun 16, 2026
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
Moderate
CVE-2026-48125
was published
for
ua-parser-js
(npm)
Jun 15, 2026
Claw Orchestrator has inefficient regular expression complexity via validateRegex()
Moderate
CVE-2026-10291
was published
for
@enderfga/claw-orchestrator
(npm)
Jun 2, 2026
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
Moderate
CVE-2026-45409
was published
for
idna
(pip)
May 19, 2026
Svelte: ReDoS in `<svelte:element>` Tag Validation
Moderate
CVE-2026-42567
was published
for
svelte
(npm)
May 14, 2026
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Moderate
CVE-2026-44796
was published
for
nautobot
(pip)
May 13, 2026
ShellHub has crash-DoS via field injection in filter and sort-by parameters
Moderate
CVE-2026-44425
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verification
Moderate
CVE-2026-35041
was published
for
fast-jwt
(npm)
Apr 9, 2026
skilleton has improper input handling in repository/path processing
Moderate
GHSA-5g3j-89fr-r2vp
was published
for
skilleton
(npm)
Apr 8, 2026
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
Moderate
CVE-2026-34939
was published
for
praisonai
(pip)
Apr 1, 2026
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards
Moderate
CVE-2026-4923
was published
for
path-to-regexp
(npm)
Mar 27, 2026
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
Moderate
CVE-2026-33169
was published
for
activesupport
(RubyGems)
Mar 23, 2026
OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction
Moderate
CVE-2026-22178
was published
for
openclaw
(npm)
Mar 2, 2026
markdown-it is has a Regular Expression Denial of Service (ReDoS)
Moderate
CVE-2026-2327
was published
for
markdown-it
(npm)
Feb 12, 2026
ajv has ReDoS when using `$data` option
Moderate
CVE-2025-69873
was published
for
ajv
(npm)
Feb 11, 2026
tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2026-22809
was published
for
tarteaucitronjs
(npm)
Jan 13, 2026
Hugging Face Transformers library has Regular Expression Denial of Service
Moderate
CVE-2025-6051
was published
for
transformers
(pip)
Sep 14, 2025
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Moderate
CVE-2025-6638
was published
for
transformers
(pip)
Sep 12, 2025
ProTip!
Advisories are also available from the
GraphQL API