Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

61 advisories

Loading
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan High
GHSA-3q6v-r5mr-hxv8 was published for league/commonmark (Composer) Sep 30, 2026
manus-pi Credited to manus-pi
mmadersbacher Credited to mmadersbacher
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict High
CVE-2026-56669 was published for elysia (npm) Sep 23, 2026
jviide Credited to jviide
Jawn: Quadratic parsing effort in AsyncParser High
CVE-2026-61814 was published for org.typelevel:jawn-parser_2.12 (Maven) Sep 23, 2026
rossabaker Credited to rossabaker and samspills samspills samspills
Plug: quadratic-time decoding of nested query/body parameters enables denial of service High
CVE-2026-54892 was published for plug (Erlang) Sep 23, 2026
braidonw Credited to braidonw, josevalim, and maennchen josevalim josevalim
maennchen maennchen
e1abrador Credited to e1abrador
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources High
CVE-2026-84375 was published for js-yaml (npm) Sep 8, 2026
xmldom: Quadratic-time attribute deduplication High
CVE-2026-83613 was published for @xmldom/xmldom (npm) Sep 8, 2026
karfau Credited to karfau
karfau Credited to karfau and Solan23 Solan23 Solan23
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
league/commonmark: Denial of service in the SmartPunct and Attributes extensions High
GHSA-jjv6-8j6v-6j52 was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y' High
GHSA-8x48-8g7j-rqxp was published for nltk (pip) Aug 27, 2026 • withdrawn
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
tonghuaroot Credited to tonghuaroot
sqlparse: Quadratic O(n²) DoS in group_comments High
CVE-2026-71491 was published for sqlparse (pip) Aug 17, 2026
sanktjodel Credited to sanktjodel and mohammedix88 mohammedix88 mohammedix88
league/commonmark: Denial of service via colliding heading slugs High
GHSA-mh25-x5hq-wrqp was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via duplicate footnote definitions High
GHSA-jfm3-95jq-q3rf was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via adjacent inline attribute blocks High
GHSA-g2gp-3wwq-f4ph was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown High
CVE-2026-71488 was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
0xsharz Credited to 0xsharz
dinhvaren Credited to dinhvaren
Shescape: Quadratic-time denial of service in the flag-protection High
CVE-2026-73413 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
js-yaml: Exponential parsing time in flow collections leads to denial of service High
CVE-2026-73643 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
ProTip! Advisories are also available from the GraphQL API