GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,830
Maven
5,000+
npm
5,000+
NuGet
1,126
pip
5,000+
Pub
13
RubyGems
1,155
Rust
1,577
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,511
Rust
20
486 advisories
Filter by severity
Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
High
GHSA-2rrw-hpqm-36pv
was published
for
nltk
(pip)
Aug 26, 2026
•
withdrawn
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
High
GHSA-5jhf-fpp7-v2pv
was published
for
nokogiri
(RubyGems)
Aug 25, 2026
•
withdrawn
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression...
High
Unreviewed
CVE-2026-66766
was published
Aug 25, 2026
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
High
CVE-2026-72818
was published
for
nltk
(pip)
Aug 21, 2026
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression...
Moderate
Unreviewed
CVE-2026-77082
was published
Aug 20, 2026
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
High
CVE-2026-59893
was published
for
sqlparse
(pip)
Aug 17, 2026
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
High
CVE-2026-54284
was published
for
sqlparse
(pip)
Aug 17, 2026
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time...
High
Unreviewed
CVE-2026-67991
was published
Aug 13, 2026
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
High
CVE-2026-67422
was published
for
pymdown-extensions
(pip)
Aug 7, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Moderate
CVE-2026-66062
was published
for
@sveltejs/kit
(npm)
Aug 7, 2026
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene...
High
Unreviewed
CVE-2026-68749
was published
Aug 6, 2026
In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular...
High
Unreviewed
CVE-2026-71190
was published
Aug 5, 2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Moderate
CVE-2026-70493
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Moderate
CVE-2026-70489
was published
for
open-webui
(pip)
Aug 4, 2026
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
Moderate
CVE-2026-69207
was published
for
hono
(npm)
Aug 3, 2026
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
High
CVE-2026-53500
was published
for
thumbor
(pip)
Jul 31, 2026
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
High
CVE-2026-12061
was published
for
nltk
(pip)
Jul 31, 2026
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1...
Moderate
Unreviewed
CVE-2026-23985
was published
Jul 30, 2026
Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the...
High
Unreviewed
CVE-2026-60075
was published
Jul 30, 2026
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Moderate
CVE-2026-59220
was published
for
open-webui
(pip)
Jul 24, 2026
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule...
Moderate
Unreviewed
CVE-2026-16270
was published
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API