Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

486 advisories

Loading
Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
GHSA-2rrw-hpqm-36pv was published for nltk (pip) Aug 26, 2026 withdrawn
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking High
GHSA-5jhf-fpp7-v2pv was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking High
CVE-2026-72818 was published for nltk (pip) Aug 21, 2026
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
tonghuaroot Credited to tonghuaroot
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header Moderate
CVE-2026-66062 was published for @sveltejs/kit (npm) Aug 7, 2026
Classic298 Credited to Classic298
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Moderate
CVE-2026-70489 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers Moderate
CVE-2026-69207 was published for hono (npm) Aug 3, 2026
sonicnew Credited to sonicnew
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex High
CVE-2026-12061 was published for nltk (pip) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config Moderate
CVE-2026-59220 was published for open-webui (pip) Jul 24, 2026
Vlad-WKG Credited to Vlad-WKG and Classic298 Classic298 Classic298
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
offset Credited to offset
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API