Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
league/commonmark's quadratic complexity bugs may lead to a denial of service High
GHSA-c2pc-g5qf-rfrf was published for league/commonmark (Composer) Dec 9, 2024
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments High
GHSA-fc86-6rv6-2jpm was published for webonyx/graphql-php (Composer) May 4, 2026
d0cs1s-bzhunt Credited to d0cs1s-bzhunt and BZHunt BZHunt BZHunt
graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation Moderate
CVE-2026-40476 was published for webonyx/graphql-php (Composer) Apr 14, 2026
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown High
CVE-2026-71488 was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via adjacent inline attribute blocks High
GHSA-g2gp-3wwq-f4ph was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via colliding heading slugs High
GHSA-mh25-x5hq-wrqp was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via duplicate footnote definitions High
GHSA-jfm3-95jq-q3rf was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark: Denial of service in the SmartPunct and Attributes extensions High
GHSA-jjv6-8j6v-6j52 was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
ProTip! Advisories are also available from the GraphQL API