GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
515 advisories
Filter by severity
Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity...
High
Unreviewed
CVE-2026-104628
was published
Oct 9, 2026
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
Moderate
CVE-2026-107290
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24...
Moderate
Unreviewed
CVE-2026-107572
was published
Oct 8, 2026
Ghost: Regular Expression Denial of Service in External Media Inliner
Moderate
CVE-2026-105645
was published
for
ghost
(npm)
Oct 7, 2026
Ghost: Regular Expression Denial of Service in Content Import
Moderate
CVE-2026-105646
was published
for
ghost
(npm)
Oct 7, 2026
Twisted: IMAP wildcardToRegexp() ReDoS
Moderate
CVE-2026-106454
was published
for
Twisted
(pip)
Oct 7, 2026
Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Quasar SSR server
High
CVE-2026-106104
was published
for
quasar
(npm)
Oct 7, 2026
Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of...
Moderate
Unreviewed
CVE-2026-102408
was published
Oct 6, 2026
Payload: ReDoS in Multipart Content-Type Validation
High
CVE-2026-105854
was published
for
payload
(npm)
Oct 6, 2026
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in...
High
Unreviewed
CVE-2026-105219
was published
Oct 4, 2026
probe-image-size: Quadratic-time Denial of Service in the SVG Parser
High
CVE-2026-104861
was published
for
probe-image-size
(npm)
Oct 2, 2026
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Moderate
CVE-2026-77387
was published
for
geopy
(pip)
Oct 2, 2026
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time...
High
Unreviewed
CVE-2026-67989
was published
Oct 2, 2026
YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php...
Moderate
Unreviewed
CVE-2026-104454
was published
Oct 2, 2026
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
High
CVE-2026-89407
was published
for
com.fasterxml.jackson.core:jackson-core
(Maven)
Oct 1, 2026
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
High
CVE-2026-102990
was published
for
basic-ftp
(npm)
Oct 1, 2026
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
High
CVE-2026-87819
was published
for
GitPython
(pip)
Sep 30, 2026
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule...
Moderate
Unreviewed
CVE-2026-100267
was published
Sep 30, 2026
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
High
CVE-2026-101903
was published
for
axios
(npm)
Sep 30, 2026
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
High
CVE-2026-101906
was published
for
axios
(npm)
Sep 30, 2026
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
Moderate
CVE-2026-102270
was published
for
pyjwt
(pip)
Sep 30, 2026
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6...
High
Unreviewed
CVE-2026-103043
was published
Sep 30, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time...
High
Unreviewed
CVE-2026-67987
was published
Sep 29, 2026
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
High
CVE-2026-92599
was published
for
joi
(npm)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API