GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
441 advisories
Filter by severity
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Moderate
CVE-2026-59220
was published
for
open-webui
(pip)
Jul 24, 2026
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule...
Moderate
Unreviewed
CVE-2026-16270
was published
Jul 22, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
High
CVE-2026-59922
was published
for
mistune
(pip)
Jul 20, 2026
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
High
CVE-2026-59925
was published
for
mistune
(pip)
Jul 20, 2026
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
High
CVE-2026-59928
was published
for
mistune
(pip)
Jul 20, 2026
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking...
High
Unreviewed
CVE-2026-14741
was published
Jul 17, 2026
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
High
CVE-2026-55574
was published
for
vllm
(pip)
Jul 17, 2026
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the...
Moderate
Unreviewed
CVE-2026-62237
was published
Jul 17, 2026
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the...
Moderate
Unreviewed
CVE-2026-6850
was published
Jul 13, 2026
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
High
CVE-2026-49851
was published
for
mistune
(pip)
Jul 9, 2026
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
Critical
CVE-2026-52778
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
High
CVE-2026-49485
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
(Maven)
Jul 9, 2026
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
High
CVE-2026-49477
was published
for
soupsieve
(pip)
Jul 9, 2026
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This...
Moderate
Unreviewed
CVE-2026-15154
was published
Jul 8, 2026
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of...
High
Unreviewed
CVE-2026-14895
was published
Jul 8, 2026
LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS)...
High
Unreviewed
CVE-2026-58578
was published
Jul 2, 2026
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
Moderate
GHSA-x4hg-hfwf-p9mw
was published
for
@asymmetric-effort/nogginlessdom
(npm)
Jul 2, 2026
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
High
CVE-2026-52746
was published
for
jsonata
(npm)
Jul 2, 2026
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
High
CVE-2026-49293
was published
for
js-toml
(npm)
Jun 26, 2026
LinkifyIt#match scan loop has quadratic algorithmic complexity
High
CVE-2026-48801
was published
for
linkify-it
(npm)
Jun 26, 2026
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS)...
Moderate
Unreviewed
CVE-2025-71379
was published
Jun 20, 2026
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
High
CVE-2026-55470
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Jun 17, 2026
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Moderate
GHSA-g75f-g53v-794x
was published
for
bleach
(pip)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API