Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

101 advisories

Loading
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns Moderate
CVE-2026-86000 was published for soupsieve (pip) Sep 17, 2026
kaimandalic Credited to kaimandalic
kaimandalic Credited to kaimandalic
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks Moderate
CVE-2026-81725 was published for nltk (pip) Sep 8, 2026
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
CVE-2026-80206 was published for nltk (pip) Sep 8, 2026
infycore Credited to infycore, ekaf, and agent-kira ekaf ekaf
agent-kira agent-kira
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
CVE-2026-80205 was published for nltk (pip) Sep 8, 2026
infycore Credited to infycore, ekaf, and agent-kira ekaf ekaf
agent-kira agent-kira
CyberKareem Credited to CyberKareem and jperezdealgaba jperezdealgaba jperezdealgaba
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
GHSA-vf76-f5cp-9846 was published for nltk (pip) Aug 31, 2026 withdrawn
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
GHSA-2rrw-hpqm-36pv was published for nltk (pip) Aug 26, 2026 withdrawn
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking High
CVE-2026-72818 was published for nltk (pip) Aug 21, 2026
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
tonghuaroot Credited to tonghuaroot
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
Classic298 Credited to Classic298
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Moderate
CVE-2026-70489 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex High
CVE-2026-12061 was published for nltk (pip) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config Moderate
CVE-2026-59220 was published for open-webui (pip) Jul 24, 2026
Vlad-WKG Credited to Vlad-WKG and Classic298 Classic298 Classic298
offset Credited to offset
offset Credited to offset
brodmart Credited to brodmart and jperezdealgaba jperezdealgaba jperezdealgaba
Mistune: Potential DoS via quadratic-time parsing in parse_link_text High
CVE-2026-49851 was published for mistune (pip) Jul 9, 2026
bhanugoudm041 Credited to bhanugoudm041
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser High
CVE-2026-49477 was published for soupsieve (pip) Jul 9, 2026
mauriceng98 Credited to mauriceng98
Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service Moderate
GHSA-vfm7-4h43-gp6m was published for vllm (pip) Jun 20, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API