GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
188 advisories
Filter by severity
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
High
GHSA-vf76-f5cp-9846
was published
for
nltk
(pip)
Aug 31, 2026
•
withdrawn
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
High
CVE-2026-57584
was published
for
phalcon/cphalcon
(Composer)
Aug 28, 2026
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-5jhf-fpp7-v2pv
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
High
CVE-2026-72818
was published
for
nltk
(pip)
Aug 21, 2026
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
High
CVE-2026-59893
was published
for
sqlparse
(pip)
Aug 17, 2026
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
High
CVE-2026-54284
was published
for
sqlparse
(pip)
Aug 17, 2026
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
High
CVE-2026-67422
was published
for
pymdown-extensions
(pip)
Aug 7, 2026
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
High
CVE-2026-53500
was published
for
thumbor
(pip)
Jul 31, 2026
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
High
CVE-2026-12061
was published
for
nltk
(pip)
Jul 31, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
High
CVE-2026-55574
was published
for
vllm
(pip)
Jul 17, 2026
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
High
CVE-2026-49851
was published
for
mistune
(pip)
Jul 9, 2026
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
High
CVE-2026-49485
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
(Maven)
Jul 9, 2026
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
High
CVE-2026-49477
was published
for
soupsieve
(pip)
Jul 9, 2026
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
High
CVE-2026-52746
was published
for
jsonata
(npm)
Jul 2, 2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
LinkifyIt#match scan loop has quadratic algorithmic complexity
High
CVE-2026-48801
was published
for
linkify-it
(npm)
Jun 26, 2026
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
High
CVE-2026-55470
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Jun 17, 2026
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
High
CVE-2026-54268
was published
for
@angular/common
(npm)
Jun 15, 2026
ProTip!
Advisories are also available from the
GraphQL API