Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
Plug: quadratic-time decoding of nested query/body parameters enables denial of service High
CVE-2026-54892 was published for plug (Erlang) Sep 23, 2026
braidonw Credited to braidonw, josevalim, and maennchen josevalim josevalim
maennchen maennchen
Absinthe: Quadratic fragment-name uniqueness check High
CVE-2026-43967 was published for absinthe (Erlang) May 14, 2026
PJUllrich Credited to PJUllrich and cschiewek cschiewek cschiewek
ProTip! Advisories are also available from the GraphQL API