Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

188 advisories

Loading
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
GHSA-vf76-f5cp-9846 was published for nltk (pip) Aug 31, 2026 withdrawn
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS High
CVE-2026-57584 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking High
GHSA-5jhf-fpp7-v2pv was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking High
CVE-2026-72818 was published for nltk (pip) Aug 21, 2026
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
tonghuaroot Credited to tonghuaroot
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex High
CVE-2026-12061 was published for nltk (pip) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
offset Credited to offset
offset Credited to offset
brodmart Credited to brodmart and jperezdealgaba jperezdealgaba jperezdealgaba
Mistune: Potential DoS via quadratic-time parsing in parse_link_text High
CVE-2026-49851 was published for mistune (pip) Jul 9, 2026
bhanugoudm041 Credited to bhanugoudm041
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint High
CVE-2026-49485 was published for ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (Maven) Jul 9, 2026
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser High
CVE-2026-49477 was published for soupsieve (pip) Jul 9, 2026
mauriceng98 Credited to mauriceng98
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion High
CVE-2026-52746 was published for jsonata (npm) Jul 2, 2026
peaktwilight Credited to peaktwilight, mattbaileyuk, and vadym-khodak mattbaileyuk mattbaileyuk
vadym-khodak vadym-khodak
tonghuaroot Credited to tonghuaroot
LinkifyIt#match scan loop has quadratic algorithmic complexity High
CVE-2026-48801 was published for linkify-it (npm) Jun 26, 2026
hillalee Credited to hillalee
ReDoS in DotVVM routing High
GHSA-c2g3-c4gc-w5wg was published for DotVVM (NuGet) Jun 19, 2026
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS High
CVE-2026-55470 was published for ca.uhn.hapi.fhir:org.hl7.fhir.convertors (Maven) Jun 17, 2026
dyingman1 Credited to dyingman1
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate) High
CVE-2026-54268 was published for @angular/common (npm) Jun 15, 2026
JeanMeche Credited to JeanMeche, alan-agius4, SkyZeroZx, and josephperrott alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx josephperrott josephperrott
ProTip! Advisories are also available from the GraphQL API