Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

485 advisories

Loading
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns Moderate
CVE-2026-86000 was published for soupsieve (pip) Sep 17, 2026
kaimandalic Credited to kaimandalic
kaimandalic Credited to kaimandalic
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends High
CVE-2026-63460 was published for vendure/core (npm) Sep 17, 2026
de3erve Credited to de3erve
Masofgon Credited to Masofgon
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing High
GHSA-j95f-988m-3j2f was published for @tiptap/core (npm) Sep 8, 2026
joostgrunwald Credited to joostgrunwald
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser High
CVE-2026-83619 was published for @xmldom/xmldom (npm) Sep 8, 2026
karfau Credited to karfau
Colord: Slow rejection of oversized malformed color strings Moderate
CVE-2026-85062 was published for colord (npm) Sep 8, 2026
GAP-dev Credited to GAP-dev
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions High
CVE-2026-83606 was published for @xmldom/xmldom (npm) Sep 8, 2026
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks Moderate
CVE-2026-81725 was published for nltk (pip) Sep 8, 2026
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
CVE-2026-80206 was published for nltk (pip) Sep 8, 2026
infycore Credited to infycore, ekaf, and agent-kira ekaf ekaf
agent-kira agent-kira
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
CVE-2026-80205 was published for nltk (pip) Sep 8, 2026
infycore Credited to infycore, ekaf, and agent-kira ekaf ekaf
agent-kira agent-kira
CyberKareem Credited to CyberKareem and jperezdealgaba jperezdealgaba jperezdealgaba
Grav: Authenticated ReDoS via regex_replace in Twig Sandbox Moderate
CVE-2026-62672 was published for getgrav/grav (Composer) Sep 2, 2026
gemstone-source Credited to gemstone-source and drpr0grammer drpr0grammer drpr0grammer
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
GHSA-vf76-f5cp-9846 was published for nltk (pip) Aug 31, 2026 withdrawn
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS High
CVE-2026-57584 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
GHSA-2rrw-hpqm-36pv was published for nltk (pip) Aug 26, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API