GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
178 advisories
Filter by severity
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
Issue summary: The QUIC stream reassembly algorithm performance deteriorates
progressively as...
Unknown
Unreviewed
CVE-2026-42772
was published
Sep 29, 2026
markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
Moderate
GHSA-253c-mchw-3w2r
was published
for
markdown-it
(npm)
Sep 29, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
Moderate
GHSA-r3ph-w7gj-g6xm
was published
for
js-yaml
(npm)
Sep 29, 2026
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free...
High
Unreviewed
CVE-2026-100700
was published
Sep 26, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
High
CVE-2026-54892
was published
for
plug
(Erlang)
Sep 23, 2026
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode...
High
Unreviewed
CVE-2026-87081
was published
Sep 22, 2026
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion...
High
Unreviewed
CVE-2026-87079
was published
Sep 22, 2026
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML...
High
Unreviewed
CVE-2026-92987
was published
Sep 17, 2026
A BIND recursive resolver may experience excessive resource consumption if it encounters large...
Moderate
Unreviewed
CVE-2026-19668
was published
Sep 16, 2026
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22...
Moderate
Unreviewed
CVE-2026-86349
was published
Sep 14, 2026
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22...
Moderate
Unreviewed
CVE-2026-12882
was published
Sep 14, 2026
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the...
High
Unreviewed
CVE-2026-90776
was published
Sep 13, 2026
t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in...
High
Unreviewed
CVE-2026-87822
was published
Sep 9, 2026
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in...
High
Unreviewed
CVE-2024-58382
was published
Sep 9, 2026
PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in...
Moderate
Unreviewed
CVE-2023-54395
was published
Sep 9, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
xmldom: Quadratic-time attribute deduplication
High
CVE-2026-83613
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
High
CVE-2026-83614
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
Moderate
CVE-2026-84378
was published
for
httpx2
(pip)
Sep 8, 2026
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
Moderate
CVE-2026-75596
was published
for
io.netty:netty-handler
(Maven)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API