Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36 advisories

Loading
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service Moderate
CVE-2026-102277 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
NotAFlightRisk Credited to NotAFlightRisk and lissy93 lissy93 lissy93
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources Moderate
GHSA-r3ph-w7gj-g6xm was published for js-yaml (npm) Sep 29, 2026
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service Moderate
CVE-2026-84378 was published for httpx2 (pip) Sep 8, 2026
GalaxySnail Credited to GalaxySnail
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing Moderate
CVE-2026-75596 was published for io.netty:netty-handler (Maven) Sep 8, 2026
mauriceng98 Credited to mauriceng98
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace Moderate
CVE-2026-82398 was published for pypdf (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y' Moderate
CVE-2026-81722 was published for nltk (pip) Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` Moderate
CVE-2026-81723 was published for nltk (pip) Sep 2, 2026
ibfavas Credited to ibfavas
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Moderate
CVE-2026-45822 was published for decode-uri-component (npm) Aug 31, 2026
bnbdr Credited to bnbdr
Hono: Algorithmic Complexity DoS in Language Middleware Moderate
CVE-2026-71848 was published for hono (npm) Aug 7, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml Moderate
CVE-2026-59868 was published for js-yaml (npm) Jul 20, 2026
mazze93 Credited to mazze93
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA Moderate
CVE-2026-59870 was published for js-yaml (npm) Jul 20, 2026
usama0x01 Credited to usama0x01
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings Moderate
CVE-2026-48516 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps Moderate
CVE-2026-48511 was published for MessagePack (NuGet) Jun 25, 2026
AArnott Credited to AArnott
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read() Moderate
CVE-2026-55206 was published for py7zr (pip) Jun 19, 2026
0xHunSec Credited to 0xHunSec
pypdf: Inefficient decoding of FlateDecode PNG predictor streams Moderate
CVE-2026-49460 was published for pypdf (pip) Jun 16, 2026
manop55555 Credited to manop55555 and stefan6419846 stefan6419846 stefan6419846
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations Moderate
CVE-2026-48988 was published for markdown-it (npm) Jun 15, 2026
tndud042713 Credited to tndud042713
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases Moderate
CVE-2026-53550 was published for js-yaml (npm) Jun 15, 2026
0xbughunter Credited to 0xbughunter, soren121, mazze93, G-Rath, dargmuesli, and omgovich soren121 soren121
mazze93 mazze93 G-Rath G-Rath dargmuesli dargmuesli omgovich omgovich
ImageMagick: Policy Bypass in MNG coder could Moderate
CVE-2026-45664 was published for Magick.NET-Q16-AnyCPU (NuGet) May 18, 2026
pucagit Credited to pucagit
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression Moderate
GHSA-q2qq-hmj6-3wpp was published for hickory-proto (Rust) May 7, 2026
qifan-sailboat Credited to qifan-sailboat
graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation Moderate
CVE-2026-40476 was published for webonyx/graphql-php (Composer) Apr 14, 2026
ProTip! Advisories are also available from the GraphQL API