Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

191 advisories

Loading
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in... High Unreviewed
CVE-2026-104426 was published Oct 2, 2026
devalue: Residual sparse-array CPU amplification in uneval Moderate
GHSA-hx4r-w6wj-j8fg was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
pypdf: Possible long runtimes with large amount of embedded files High
CVE-2026-102999 was published for pypdf (pip) Oct 1, 2026
jungmingi-lab Credited to jungmingi-lab
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) High
CVE-2026-102997 was published for pypdf (pip) Oct 1, 2026
geoffrey-diederichs Credited to geoffrey-diederichs and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes/large memory usage when parsing indirect objects High
CVE-2026-102994 was published for pypdf (pip) Oct 1, 2026
jankesec Credited to jankesec and stefan6419846 stefan6419846 stefan6419846
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan High
GHSA-3q6v-r5mr-hxv8 was published for league/commonmark (Composer) Sep 30, 2026
manus-pi Credited to manus-pi
mmadersbacher Credited to mmadersbacher
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service Moderate
CVE-2026-102277 was published for brace-expansion (npm) Sep 29, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service High
GHSA-v53p-9fqp-m79j was published for nodemailer (npm) Sep 29, 2026
NotAFlightRisk Credited to NotAFlightRisk and lissy93 lissy93 lissy93
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources Moderate
GHSA-r3ph-w7gj-g6xm was published for js-yaml (npm) Sep 29, 2026
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict High
CVE-2026-56669 was published for elysia (npm) Sep 23, 2026
jviide Credited to jviide
Jawn: Quadratic parsing effort in AsyncParser High
CVE-2026-61814 was published for org.typelevel:jawn-parser_2.12 (Maven) Sep 23, 2026
rossabaker Credited to rossabaker and samspills samspills samspills
Plug: quadratic-time decoding of nested query/body parameters enables denial of service High
CVE-2026-54892 was published for plug (Erlang) Sep 23, 2026
braidonw Credited to braidonw, josevalim, and maennchen josevalim josevalim
maennchen maennchen
ProTip! Advisories are also available from the GraphQL API