Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

515 advisories

Loading
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` Moderate
CVE-2026-107290 was published for pydantic-ai (pip) Oct 8, 2026
BrianWillows Credited to BrianWillows
Ghost: Regular Expression Denial of Service in External Media Inliner Moderate
CVE-2026-105645 was published for ghost (npm) Oct 7, 2026
ka3n1x Credited to ka3n1x
Ghost: Regular Expression Denial of Service in Content Import Moderate
CVE-2026-105646 was published for ghost (npm) Oct 7, 2026
ka3n1x Credited to ka3n1x
Twisted: IMAP wildcardToRegexp() ReDoS Moderate
CVE-2026-106454 was published for Twisted (pip) Oct 7, 2026
sharanxP Credited to sharanxP
fg0x0 Credited to fg0x0 and hawkeye64 hawkeye64 hawkeye64
Payload: ReDoS in Multipart Content-Type Validation High
CVE-2026-105854 was published for payload (npm) Oct 6, 2026
hwpark6804-gif Credited to hwpark6804-gif
probe-image-size: Quadratic-time Denial of Service in the SVG Parser High
CVE-2026-104861 was published for probe-image-size (npm) Oct 2, 2026
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point Moderate
CVE-2026-77387 was published for geopy (pip) Oct 2, 2026
gnsehfvlr Credited to gnsehfvlr, apoorvdarshan, and KostyaEsmukov apoorvdarshan apoorvdarshan
KostyaEsmukov KostyaEsmukov
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() High
CVE-2026-89407 was published for com.fasterxml.jackson.core:jackson-core (Maven) Oct 1, 2026
manqingzhou Credited to manqingzhou
NotAFlightRisk Credited to NotAFlightRisk
prvazsahnazarov Credited to prvazsahnazarov and manus-use manus-use manus-use
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) High
CVE-2026-101903 was published for axios (npm) Sep 30, 2026
Frentzen Credited to Frentzen
Zandereins Credited to Zandereins
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. Moderate
CVE-2026-102270 was published for pyjwt (pip) Sep 30, 2026
Yanni8 Credited to Yanni8
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()` High
CVE-2026-92599 was published for joi (npm) Sep 29, 2026
qrn12580 Credited to qrn12580 and yfwmaniish yfwmaniish yfwmaniish
ProTip! Advisories are also available from the GraphQL API