Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

124 advisories

Loading
CyberKareem Credited to CyberKareem and jperezdealgaba jperezdealgaba jperezdealgaba
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header Moderate
CVE-2026-66062 was published for @sveltejs/kit (npm) Aug 7, 2026
Classic298 Credited to Classic298
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Moderate
CVE-2026-70489 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers Moderate
CVE-2026-69207 was published for hono (npm) Aug 3, 2026
sonicnew Credited to sonicnew
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config Moderate
CVE-2026-59220 was published for open-webui (pip) Jul 24, 2026
Vlad-WKG Credited to Vlad-WKG and Classic298 Classic298 Classic298
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation Moderate
GHSA-x4hg-hfwf-p9mw was published for @asymmetric-effort/nogginlessdom (npm) Jul 2, 2026
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning Moderate
GHSA-g75f-g53v-794x was published for bleach (pip) Jun 16, 2026
0xHunSec Credited to 0xHunSec
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()` Moderate
CVE-2026-48125 was published for ua-parser-js (npm) Jun 15, 2026
sondt99 Credited to sondt99
Claw Orchestrator has inefficient regular expression complexity via validateRegex() Moderate
CVE-2026-10291 was published for @enderfga/claw-orchestrator (npm) Jun 2, 2026
StanFromIreland Credited to StanFromIreland and kjd kjd kjd
Svelte: ReDoS in `<svelte:element>` Tag Validation Moderate
CVE-2026-42567 was published for svelte (npm) May 14, 2026
Meltedd Credited to Meltedd, dummdidumm, and elliott-with-the-longest-name-on-github dummdidumm dummdidumm
elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
whatisproblem Credited to whatisproblem
ShellHub has crash-DoS via field injection in filter and sort-by parameters Moderate
CVE-2026-44425 was published for github.com/shellhub-io/shellhub (Go) May 6, 2026
Edu0x01 Credited to Edu0x01
fasrm Credited to fasrm and SociableSteve SociableSteve SociableSteve
skilleton has improper input handling in repository/path processing Moderate
GHSA-5g3j-89fr-r2vp was published for skilleton (npm) Apr 8, 2026
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools() Moderate
CVE-2026-34939 was published for praisonai (pip) Apr 1, 2026
YeranG30 Credited to YeranG30
path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards Moderate
CVE-2026-4923 was published for path-to-regexp (npm) Mar 27, 2026
blakeembrey Credited to blakeembrey and UlisesGascon UlisesGascon UlisesGascon
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited Moderate
CVE-2026-33169 was published for activesupport (RubyGems) Mar 23, 2026
ch4n3-yoon Credited to ch4n3-yoon
OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction Moderate
CVE-2026-22178 was published for openclaw (npm) Mar 2, 2026
markdown-it is has a Regular Expression Denial of Service (ReDoS) Moderate
CVE-2026-2327 was published for markdown-it (npm) Feb 12, 2026
ajv has ReDoS when using `$data` option Moderate
CVE-2025-69873 was published for ajv (npm) Feb 11, 2026
epoberezkin Credited to epoberezkin, G-Rath, and wayne530 G-Rath G-Rath
wayne530 wayne530
tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability Moderate
CVE-2026-22809 was published for tarteaucitronjs (npm) Jan 13, 2026
Yasha-ops Credited to Yasha-ops
Hugging Face Transformers library has Regular Expression Denial of Service Moderate
CVE-2025-6051 was published for transformers (pip) Sep 14, 2025
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer Moderate
CVE-2025-6638 was published for transformers (pip) Sep 12, 2025
ProTip! Advisories are also available from the GraphQL API