GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,798
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
485 advisories
Filter by severity
An inefficient regular expression complexity issue in the in-memory query evaluation component of...
High
Unreviewed
CVE-2026-93761
was published
Sep 18, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Moderate
CVE-2026-86000
was published
for
soupsieve
(pip)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Moderate
CVE-2026-85999
was published
for
soupsieve
(pip)
Sep 17, 2026
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
High
CVE-2026-63460
was published
for
vendure/core
(npm)
Sep 17, 2026
joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable...
High
Unreviewed
CVE-2026-92599
was published
Sep 17, 2026
The two built-in name-finder patterns exposed by
opennlp.tools.namefind.RegexNameFinderFactory -...
Critical
Unreviewed
CVE-2026-82617
was published
Sep 11, 2026
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
High
CVE-2026-86081
was published
for
n8n
(npm)
Sep 10, 2026
An authenticated client could attach a consumer with a selector containing crafted wildcard usage...
Unknown
Unreviewed
CVE-2026-75880
was published
Sep 10, 2026
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor...
High
Unreviewed
CVE-2026-87819
was published
Sep 9, 2026
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
High
GHSA-j95f-988m-3j2f
was published
for
@tiptap/core
(npm)
Sep 8, 2026
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
High
CVE-2026-83619
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
Colord: Slow rejection of oversized malformed color strings
Moderate
CVE-2026-85062
was published
for
colord
(npm)
Sep 8, 2026
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
High
CVE-2026-83606
was published
for
@xmldom/xmldom
(npm)
Sep 8, 2026
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
Moderate
CVE-2026-81725
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
High
CVE-2026-80206
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
High
CVE-2026-80205
was published
for
nltk
(pip)
Sep 8, 2026
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
Grav: Authenticated ReDoS via regex_replace in Twig Sandbox
Moderate
CVE-2026-62672
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a...
High
Unreviewed
CVE-2026-84642
was published
Sep 2, 2026
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
High
GHSA-j8pm-gj4c-rq4x
was published
for
league/commonmark
(Composer)
Sep 1, 2026
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
High
GHSA-vf76-f5cp-9846
was published
for
nltk
(pip)
Aug 31, 2026
•
withdrawn
nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email...
Moderate
Unreviewed
CVE-2024-58379
was published
Aug 31, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
High
CVE-2026-57584
was published
for
phalcon/cphalcon
(Composer)
Aug 28, 2026
Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
High
GHSA-2rrw-hpqm-36pv
was published
for
nltk
(pip)
Aug 26, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API