GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
34 advisories
Filter by severity
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
High
CVE-2026-27903
was published
for
minimatch
(npm)
Feb 26, 2026
parse-server has GraphQL complexity validator exponential fragment traversal DoS
High
CVE-2026-34573
was published
for
parse-server
(npm)
Mar 31, 2026
Pretext: Algorithmic Complexity (DoS) in the text analysis phase
High
GHSA-5478-66c3-rhxr
was published
for
@chenglou/pretext
(npm)
Apr 8, 2026
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
Moderate
CVE-2026-53550
was published
for
js-yaml
(npm)
Jun 15, 2026
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
Moderate
CVE-2026-48988
was published
for
markdown-it
(npm)
Jun 15, 2026
parse-server: Denial of service via exponential-time processing of deeply nested query operators
High
GHSA-cgxm-vr2f-6fj8
was published
for
parse-server
(npm)
Jun 19, 2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
High
CVE-2026-49250
was published
for
@conform-to/dom
(npm)
Jul 2, 2026
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
High
CVE-2026-13149
was published
for
brace-expansion
(npm)
Jul 20, 2026
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
Moderate
CVE-2026-59870
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
High
CVE-2026-13311
was published
for
shell-quote
(npm)
Jul 20, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
High
CVE-2026-59887
was published
for
linkify-it
(npm)
Jul 21, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
CVE-2026-73643
was published
for
js-yaml
(npm)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
CVE-2026-73413
was published
for
shescape
(npm)
Jul 24, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
High
GHSA-5p4m-2wfm-xmqj
was published
for
js-yaml
(npm)
Aug 6, 2026
Hono: Algorithmic Complexity DoS in Language Middleware
Moderate
CVE-2026-71848
was published
for
hono
(npm)
Aug 7, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
High
CVE-2026-83614
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API