GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
191 advisories
Filter by severity
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.
This issue...
High
Unreviewed
CVE-2026-96287
was published
Oct 2, 2026
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity...
High
Unreviewed
CVE-2026-94655
was published
Oct 2, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue...
High
Unreviewed
CVE-2026-94658
was published
Oct 2, 2026
Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in...
High
Unreviewed
CVE-2026-96292
was published
Oct 2, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings.
This issue...
High
Unreviewed
CVE-2026-94653
was published
Oct 2, 2026
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in...
High
Unreviewed
CVE-2026-104426
was published
Oct 2, 2026
Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name...
High
Unreviewed
CVE-2026-103604
was published
Oct 2, 2026
devalue: Residual sparse-array CPU amplification in uneval
Moderate
GHSA-hx4r-w6wj-j8fg
was published
for
devalue
(npm)
Oct 1, 2026
pypdf: Possible long runtimes with large amount of embedded files
High
CVE-2026-102999
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
High
CVE-2026-102997
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
High
CVE-2026-102994
was published
for
pypdf
(pip)
Oct 1, 2026
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan
High
GHSA-3q6v-r5mr-hxv8
was published
for
league/commonmark
(Composer)
Sep 30, 2026
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
High
GHSA-prgh-xp8r-p3m5
was published
for
nodemailer
(npm)
Sep 30, 2026
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
Moderate
CVE-2026-102277
was published
for
brace-expansion
(npm)
Sep 29, 2026
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
High
GHSA-v53p-9fqp-m79j
was published
for
nodemailer
(npm)
Sep 29, 2026
Issue summary: The QUIC stream reassembly algorithm performance deteriorates
progressively as...
Moderate
Unreviewed
CVE-2026-42772
was published
Sep 29, 2026
markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
Moderate
GHSA-253c-mchw-3w2r
was published
for
markdown-it
(npm)
Sep 29, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
Moderate
GHSA-r3ph-w7gj-g6xm
was published
for
js-yaml
(npm)
Sep 29, 2026
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free...
High
Unreviewed
CVE-2026-100700
was published
Sep 26, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
High
CVE-2026-56669
was published
for
elysia
(npm)
Sep 23, 2026
Jawn: Quadratic parsing effort in AsyncParser
High
CVE-2026-61814
was published
for
org.typelevel:jawn-parser_2.12
(Maven)
Sep 23, 2026
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
High
CVE-2026-54892
was published
for
plug
(Erlang)
Sep 23, 2026
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode...
High
Unreviewed
CVE-2026-87081
was published
Sep 22, 2026
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion...
High
Unreviewed
CVE-2026-87079
was published
Sep 22, 2026
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML...
High
Unreviewed
CVE-2026-92987
was published
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API