Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34 advisories

Loading
dolevmiz1 Credited to dolevmiz1
parse-server has GraphQL complexity validator exponential fragment traversal DoS High
CVE-2026-34573 was published for parse-server (npm) Mar 31, 2026
bugbunny-research Credited to bugbunny-research and mtrezza mtrezza mtrezza
Pretext: Algorithmic Complexity (DoS) in the text analysis phase High
GHSA-5478-66c3-rhxr was published for @chenglou/pretext (npm) Apr 8, 2026
NapongiZero Credited to NapongiZero
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases Moderate
CVE-2026-53550 was published for js-yaml (npm) Jun 15, 2026
0xbughunter Credited to 0xbughunter, soren121, mazze93, G-Rath, dargmuesli, and omgovich soren121 soren121
mazze93 mazze93 G-Rath G-Rath dargmuesli dargmuesli omgovich omgovich
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations Moderate
CVE-2026-48988 was published for markdown-it (npm) Jun 15, 2026
tndud042713 Credited to tndud042713
parse-server: Denial of service via exponential-time processing of deeply nested query operators High
GHSA-cgxm-vr2f-6fj8 was published for parse-server (npm) Jun 19, 2026
sajdakabir Credited to sajdakabir, mtrezza, zerotrail-ai, and immadsahin mtrezza mtrezza
zerotrail-ai zerotrail-ai immadsahin immadsahin
tonghuaroot Credited to tonghuaroot and PROVA-bingrrr PROVA-bingrrr PROVA-bingrrr
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields High
CVE-2026-49250 was published for @conform-to/dom (npm) Jul 2, 2026
jviide Credited to jviide
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups High
CVE-2026-13149 was published for brace-expansion (npm) Jul 20, 2026
bnbdr Credited to bnbdr, ljharb, and juliangruber ljharb ljharb
juliangruber juliangruber
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
js-yaml: YAML merge-key chains can force quadratic CPU consumption High
CVE-2026-59869 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) High
CVE-2026-13311 was published for shell-quote (npm) Jul 20, 2026
bibu123456 Credited to bibu123456, Kayiz-PT, and ljharb Kayiz-PT Kayiz-PT
ljharb ljharb
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth, 36degrees, jdeniau, chintan-ladani-coherent, ravali-ch15, and domcleal 36degrees 36degrees
jdeniau jdeniau chintan-ladani-coherent chintan-ladani-coherent ravali-ch15 ravali-ch15 domcleal domcleal
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text High
CVE-2026-59887 was published for linkify-it (npm) Jul 21, 2026
bibu123456 Credited to bibu123456 and Kayiz-PT Kayiz-PT Kayiz-PT
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
js-yaml: Exponential parsing time in flow collections leads to denial of service High
CVE-2026-73643 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
Shescape: Quadratic-time denial of service in the flag-protection High
CVE-2026-73413 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
dinhvaren Credited to dinhvaren
0xsharz Credited to 0xsharz
Hono: Algorithmic Complexity DoS in Language Middleware Moderate
CVE-2026-71848 was published for hono (npm) Aug 7, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Moderate
CVE-2026-45822 was published for decode-uri-component (npm) Aug 31, 2026
bnbdr Credited to bnbdr
karfau Credited to karfau and Solan23 Solan23 Solan23
ProTip! Advisories are also available from the GraphQL API