GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
100 advisories
Filter by severity
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free...
High
Unreviewed
CVE-2026-100700
was published
Sep 26, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
High
CVE-2026-54892
was published
for
plug
(Erlang)
Sep 23, 2026
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode...
High
Unreviewed
CVE-2026-87081
was published
Sep 22, 2026
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion...
High
Unreviewed
CVE-2026-87079
was published
Sep 22, 2026
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML...
High
Unreviewed
CVE-2026-92987
was published
Sep 17, 2026
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the...
High
Unreviewed
CVE-2026-90776
was published
Sep 13, 2026
t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in...
High
Unreviewed
CVE-2026-87822
was published
Sep 9, 2026
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in...
High
Unreviewed
CVE-2024-58382
was published
Sep 9, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
xmldom: Quadratic-time attribute deduplication
High
CVE-2026-83613
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
High
CVE-2026-83614
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the...
High
Unreviewed
CVE-2026-86428
was published
Sep 7, 2026
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in...
High
Unreviewed
CVE-2026-86430
was published
Sep 7, 2026
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the...
High
Unreviewed
CVE-2026-86433
was published
Sep 7, 2026
league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service...
High
Unreviewed
CVE-2026-86434
was published
Sep 7, 2026
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the...
High
Unreviewed
CVE-2026-86435
was published
Sep 7, 2026
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains...
High
Unreviewed
CVE-2026-86429
was published
Sep 7, 2026
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms...
High
Unreviewed
CVE-2026-85446
was published
Sep 4, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
High
GHSA-jjv6-8j6v-6j52
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API