Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

29 advisories

Loading
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service Moderate
CVE-2026-84378 was published for httpx2 (pip) Sep 8, 2026
GalaxySnail Credited to GalaxySnail
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace Moderate
CVE-2026-82398 was published for pypdf (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y' Moderate
CVE-2026-81722 was published for nltk (pip) Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` Moderate
CVE-2026-81723 was published for nltk (pip) Sep 2, 2026
ibfavas Credited to ibfavas
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y' High
GHSA-8x48-8g7j-rqxp was published for nltk (pip) Aug 27, 2026 • withdrawn
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
tonghuaroot Credited to tonghuaroot
sqlparse: Quadratic O(n²) DoS in group_comments High
CVE-2026-71491 was published for sqlparse (pip) Aug 17, 2026
sanktjodel Credited to sanktjodel and mohammedix88 mohammedix88 mohammedix88
tynus2 Credited to tynus2
offset Credited to offset
offset Credited to offset
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read() Moderate
CVE-2026-55206 was published for py7zr (pip) Jun 19, 2026
0xHunSec Credited to 0xHunSec
pypdf: Inefficient decoding of FlateDecode PNG predictor streams Moderate
CVE-2026-49460 was published for pypdf (pip) Jun 16, 2026
manop55555 Credited to manop55555 and stefan6419846 stefan6419846 stefan6419846
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service High
CVE-2026-53539 was published for python-multipart (pip) Jun 15, 2026
maxisbey Credited to maxisbey
justhtml introduces denial-of-service hardening Low
GHSA-r8cj-3554-33mr was published for justhtml (pip) May 8, 2026
EmilStenstrom Credited to EmilStenstrom
tomasilluminati Credited to tomasilluminati
Django has potential DoS via MultiPartParser through crafted multipart uploads Moderate
CVE-2026-33033 was published for Django (pip) Apr 7, 2026
pypdf has inefficient decoding of array-based streams Moderate
CVE-2026-33123 was published for pypdf (pip) Mar 18, 2026
kule500 Credited to kule500 and stefan6419846 stefan6419846 stefan6419846
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams Moderate
CVE-2026-28804 was published for pypdf (pip) Mar 2, 2026
kule500 Credited to kule500 and stefan6419846 stefan6419846 stefan6419846
Django has Inefficient Algorithmic Complexity Low
CVE-2025-14550 was published for Django (pip) Feb 3, 2026
Django has Inefficient Algorithmic Complexity Low
CVE-2026-1285 was published for Django (pip) Feb 3, 2026
Django is vulnerable to DoS via XML serializer text extraction Moderate
CVE-2025-64460 was published for Django (pip) Dec 2, 2025
ProTip! Advisories are also available from the GraphQL API