GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
34 advisories
Filter by severity
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
High
GHSA-prgh-xp8r-p3m5
was published
for
nodemailer
(npm)
Sep 30, 2026
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
Moderate
GHSA-253c-mchw-3w2r
was published
for
markdown-it
(npm)
Sep 29, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
Moderate
GHSA-r3ph-w7gj-g6xm
was published
for
js-yaml
(npm)
Sep 29, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
xmldom: Quadratic-time attribute deduplication
High
CVE-2026-83613
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
High
CVE-2026-83614
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
High
CVE-2026-59880
was published
for
immutable
(npm)
Jul 21, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
CVE-2026-73643
was published
for
js-yaml
(npm)
Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection
High
CVE-2026-73413
was published
for
shescape
(npm)
Jul 24, 2026
Hono: Algorithmic Complexity DoS in Language Middleware
Moderate
CVE-2026-71848
was published
for
hono
(npm)
Aug 7, 2026
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
High
GHSA-5p4m-2wfm-xmqj
was published
for
js-yaml
(npm)
Aug 6, 2026
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
High
CVE-2026-71321
was published
for
nuxt
(npm)
Aug 5, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
High
CVE-2026-55685
was published
for
react-router
(npm)
Jul 24, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
High
CVE-2026-59887
was published
for
linkify-it
(npm)
Jul 21, 2026
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)
High
CVE-2026-13311
was published
for
shell-quote
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
Moderate
CVE-2026-59870
was published
for
js-yaml
(npm)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API