GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36 advisories
Filter by severity
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
Moderate
GHSA-253c-mchw-3w2r
was published
for
markdown-it
(npm)
Sep 29, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
Moderate
GHSA-r3ph-w7gj-g6xm
was published
for
js-yaml
(npm)
Sep 29, 2026
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
Moderate
CVE-2026-84378
was published
for
httpx2
(pip)
Sep 8, 2026
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
Moderate
CVE-2026-75596
was published
for
io.netty:netty-handler
(Maven)
Sep 8, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
Moderate
CVE-2026-82398
was published
for
pypdf
(pip)
Sep 2, 2026
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
Moderate
CVE-2026-81722
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
Moderate
CVE-2026-81723
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
Moderate
CVE-2026-12876
was published
for
nltk
(pip)
Sep 2, 2026
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
Moderate
CVE-2026-84305
was published
for
sqlparse
(pip)
Sep 1, 2026
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
Moderate
CVE-2026-45822
was published
for
decode-uri-component
(npm)
Aug 31, 2026
Hono: Algorithmic Complexity DoS in Language Middleware
Moderate
CVE-2026-71848
was published
for
hono
(npm)
Aug 7, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
Moderate
CVE-2026-59870
was published
for
js-yaml
(npm)
Jul 20, 2026
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
Moderate
CVE-2026-48516
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
Moderate
CVE-2026-48511
was published
for
MessagePack
(NuGet)
Jun 25, 2026
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
Moderate
CVE-2026-55206
was published
for
py7zr
(pip)
Jun 19, 2026
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
Moderate
CVE-2026-49460
was published
for
pypdf
(pip)
Jun 16, 2026
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
Moderate
CVE-2026-48988
was published
for
markdown-it
(npm)
Jun 15, 2026
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
Moderate
CVE-2026-53550
was published
for
js-yaml
(npm)
Jun 15, 2026
ImageMagick: Policy Bypass in MNG coder could
Moderate
CVE-2026-45664
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
Moderate
GHSA-q2qq-hmj6-3wpp
was published
for
hickory-proto
(Rust)
May 7, 2026
graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
Moderate
CVE-2026-40476
was published
for
webonyx/graphql-php
(Composer)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API