GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,153
Maven
5,000+
npm
5,000+
NuGet
861
pip
4,451
Pub
12
RubyGems
991
Rust
1,179
Swift
50
Unreviewed advisories
All unreviewed
5,000+
286 advisories
Filter by severity
multipart vulnerable to ReDoS in `parse_options_header()`
High
CVE-2026-28356
was published
for
multipart
(pip)
Mar 12, 2026
Elysia has a string URL format ReDoS
High
CVE-2026-30837
was published
for
elysia
(npm)
Mar 10, 2026
Parse Server has Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
High
CVE-2026-30925
was published
for
parse-server
(npm)
Mar 10, 2026
OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction
Moderate
GHSA-c6hr-w26q-c636
was published
for
openclaw
(npm)
Mar 2, 2026
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
High
CVE-2026-27904
was published
for
minimatch
(npm)
Feb 26, 2026
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
High
CVE-2026-26996
was published
for
minimatch
(npm)
Feb 18, 2026
markdown-it is has a Regular Expression Denial of Service (ReDoS)
Moderate
CVE-2026-2327
was published
for
markdown-it
(npm)
Feb 12, 2026
ajv has ReDoS when using `$data` option
Moderate
CVE-2025-69873
was published
for
ajv
(npm)
Feb 11, 2026
Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`
High
CVE-2026-23897
was published
for
@apollo/server
(npm)
Feb 4, 2026
@isaacs/brace-expansion has Uncontrolled Resource Consumption
High
CVE-2026-25547
was published
for
@isaacs/brace-expansion
(npm)
Feb 3, 2026
seroval affected by Denial of Service via RegExp serialization
High
CVE-2026-23956
was published
for
seroval
(npm)
Jan 21, 2026
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Low
CVE-2026-24001
was published
for
diff
(npm)
Jan 14, 2026
tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2026-22809
was published
for
tarteaucitronjs
(npm)
Jan 13, 2026
pypdf has possible long runtimes for malformed startxref
Low
CVE-2026-22691
was published
for
pypdf
(pip)
Jan 9, 2026
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
High
CVE-2026-0621
was published
for
@modelcontextprotocol/sdk
(npm)
Jan 5, 2026
Fedify has ReDoS Vulnerability in HTML Parsing Regex
High
CVE-2025-68475
was published
for
@fedify/fedify
(npm)
Dec 22, 2025
PyMdown Extensions has a ReDOS bug in its Figure Capture extension
Low
CVE-2025-68142
was published
for
pymdown-extensions
(pip)
Dec 16, 2025
Valibot has a ReDoS vulnerability in `EMOJI_REGEX`
High
CVE-2025-66020
was published
for
valibot
(npm)
Nov 26, 2025
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
Low
CVE-2025-61581
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Oct 16, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
CVE-2025-61921
was published
for
sinatra
(RubyGems)
Oct 10, 2025
Hugging Face Transformers library has Regular Expression Denial of Service
Moderate
CVE-2025-6051
was published
for
transformers
(pip)
Sep 14, 2025
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Moderate
CVE-2025-6638
was published
for
transformers
(pip)
Sep 12, 2025
Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity
High
CVE-2025-58451
was published
for
cattown
(npm)
Sep 9, 2025
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Moderate
CVE-2025-43764
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Aug 23, 2025
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54364
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API