GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
61 advisories
Filter by severity
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan
High
GHSA-3q6v-r5mr-hxv8
was published
for
league/commonmark
(Composer)
Sep 30, 2026
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
High
GHSA-prgh-xp8r-p3m5
was published
for
nodemailer
(npm)
Sep 30, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
High
CVE-2026-54892
was published
for
plug
(Erlang)
Sep 23, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
xmldom: Quadratic-time attribute deduplication
High
CVE-2026-83613
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
High
CVE-2026-83614
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
High
GHSA-8rr7-cvq3-gmfh
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
High
GHSA-jjv6-8j6v-6j52
was published
for
league/commonmark
(Composer)
Sep 1, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y'
High
GHSA-8x48-8g7j-rqxp
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
High
CVE-2026-54284
was published
for
sqlparse
(pip)
Aug 17, 2026
sqlparse: Quadratic O(n²) DoS in group_comments
High
CVE-2026-71491
was published
for
sqlparse
(pip)
Aug 17, 2026
league/commonmark: Denial of service via colliding heading slugs
High
GHSA-mh25-x5hq-wrqp
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via duplicate footnote definitions
High
GHSA-jfm3-95jq-q3rf
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via adjacent inline attribute blocks
High
GHSA-g2gp-3wwq-f4ph
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
High
CVE-2026-71488
was published
for
league/commonmark
(Composer)
Aug 6, 2026
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
High
GHSA-5p4m-2wfm-xmqj
was published
for
js-yaml
(npm)
Aug 6, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
CVE-2026-73413
was published
for
shescape
(npm)
Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
CVE-2026-73643
was published
for
js-yaml
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API