Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

184 advisories

Loading
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
tynus2 Credited to tynus2
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text High
CVE-2026-59887 was published for linkify-it (npm) Jul 21, 2026
bibu123456 Credited to bibu123456 and Kayiz-PT Kayiz-PT Kayiz-PT
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth, 36degrees, jdeniau, chintan-ladani-coherent, ravali-ch15, and domcleal 36degrees 36degrees
jdeniau jdeniau chintan-ladani-coherent chintan-ladani-coherent ravali-ch15 ravali-ch15 domcleal domcleal
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) High
CVE-2026-13311 was published for shell-quote (npm) Jul 20, 2026
bibu123456 Credited to bibu123456, Kayiz-PT, and ljharb Kayiz-PT Kayiz-PT
ljharb ljharb
offset Credited to offset
offset Credited to offset
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: YAML merge-key chains can force quadratic CPU consumption High
CVE-2026-59869 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups High
CVE-2026-13149 was published for brace-expansion (npm) Jul 20, 2026
bnbdr Credited to bnbdr, ljharb, and juliangruber ljharb ljharb
juliangruber juliangruber
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields High
CVE-2026-49250 was published for @conform-to/dom (npm) Jul 2, 2026
jviide Credited to jviide
fzf vulnerable to denial of service through quadratic HTTP request-body accumulation Moderate
CVE-2026-53433 was published for github.com/junegunn/fzf (Go) Jun 30, 2026
tonghuaroot Credited to tonghuaroot and PROVA-bingrrr PROVA-bingrrr PROVA-bingrrr
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings Moderate
CVE-2026-48516 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps Moderate
CVE-2026-48511 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
AArnott Credited to AArnott
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read() Moderate
CVE-2026-55206 was published for py7zr (pip) Jun 19, 2026
0xHunSec Credited to 0xHunSec
parse-server: Denial of service via exponential-time processing of deeply nested query operators High
GHSA-cgxm-vr2f-6fj8 was published for parse-server (npm) Jun 19, 2026
sajdakabir Credited to sajdakabir, mtrezza, zerotrail-ai, and immadsahin mtrezza mtrezza
zerotrail-ai zerotrail-ai immadsahin immadsahin
pypdf: Inefficient decoding of FlateDecode PNG predictor streams Moderate
CVE-2026-49460 was published for pypdf (pip) Jun 16, 2026
manop55555 Credited to manop55555 and stefan6419846 stefan6419846 stefan6419846
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations Moderate
CVE-2026-48988 was published for markdown-it (npm) Jun 15, 2026
tndud042713 Credited to tndud042713
ProTip! Advisories are also available from the GraphQL API