Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34 advisories

Loading
mmadersbacher Credited to mmadersbacher
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service Moderate
CVE-2026-102277 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
NotAFlightRisk Credited to NotAFlightRisk and lissy93 lissy93 lissy93
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources Moderate
GHSA-r3ph-w7gj-g6xm was published for js-yaml (npm) Sep 29, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict High
CVE-2026-56669 was published for elysia (npm) Sep 23, 2026
jviide Credited to jviide
e1abrador Credited to e1abrador
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources High
CVE-2026-84375 was published for js-yaml (npm) Sep 8, 2026
xmldom: Quadratic-time attribute deduplication High
CVE-2026-83613 was published for @xmldom/xmldom (npm) Sep 8, 2026
karfau Credited to karfau
karfau Credited to karfau and Solan23 Solan23 Solan23
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth, 36degrees, jdeniau, chintan-ladani-coherent, ravali-ch15, and domcleal 36degrees 36degrees
jdeniau jdeniau chintan-ladani-coherent chintan-ladani-coherent ravali-ch15 ravali-ch15 domcleal domcleal
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Moderate
CVE-2026-45822 was published for decode-uri-component (npm) Aug 31, 2026
bnbdr Credited to bnbdr
js-yaml: Exponential parsing time in flow collections leads to denial of service High
CVE-2026-73643 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
Shescape: Quadratic-time denial of service in the flag-protection High
CVE-2026-73413 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Hono: Algorithmic Complexity DoS in Language Middleware Moderate
CVE-2026-71848 was published for hono (npm) Aug 7, 2026
0xsharz Credited to 0xsharz
dinhvaren Credited to dinhvaren
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text High
CVE-2026-59887 was published for linkify-it (npm) Jul 21, 2026
bibu123456 Credited to bibu123456 and Kayiz-PT Kayiz-PT Kayiz-PT
shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407) High
CVE-2026-13311 was published for shell-quote (npm) Jul 20, 2026
bibu123456 Credited to bibu123456, Kayiz-PT, and ljharb Kayiz-PT Kayiz-PT
ljharb ljharb
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: YAML merge-key chains can force quadratic CPU consumption High
CVE-2026-59869 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
ProTip! Advisories are also available from the GraphQL API