GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
208 advisories
Filter by severity
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>
High
CVE-2026-107378
was published
for
cairosvg
(pip)
Oct 8, 2026
Pydantic AI: Excessive resource use when local web fetching converts nested HTML
Moderate
CVE-2026-107287
was published
for
pydantic-ai
(pip)
Oct 8, 2026
msgpack5: Quadratic parsing in the streaming decoder
Moderate
CVE-2026-107297
was published
for
msgpack5
(npm)
Oct 8, 2026
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
Moderate
CVE-2026-107290
was published
for
pydantic-ai
(pip)
Oct 8, 2026
Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of...
High
Unreviewed
CVE-2026-107576
was published
Oct 8, 2026
Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6...
Moderate
Unreviewed
CVE-2026-107575
was published
Oct 8, 2026
Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot...
High
Unreviewed
CVE-2026-107579
was published
Oct 8, 2026
Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed...
Moderate
Unreviewed
CVE-2026-107581
was published
Oct 8, 2026
Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW...
Moderate
Unreviewed
CVE-2026-107582
was published
Oct 8, 2026
Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot...
Moderate
Unreviewed
CVE-2026-107580
was published
Oct 8, 2026
Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive...
Moderate
Unreviewed
CVE-2026-107583
was published
Oct 8, 2026
Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a...
High
Unreviewed
CVE-2026-107574
was published
Oct 8, 2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does...
Moderate
Unreviewed
CVE-2026-76271
was published
Oct 7, 2026
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18.
...
Moderate
Unreviewed
CVE-2026-84429
was published
Oct 6, 2026
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
Moderate
GHSA-r4xh-jqrq-34v2
was published
for
smol-toml
(npm)
Oct 5, 2026
PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion
Moderate
CVE-2026-104844
was published
for
postcss-selector-parser
(npm)
Oct 5, 2026
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
Moderate
CVE-2026-104182
was published
for
stream-json
(npm)
Oct 5, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings.
This issue...
High
Unreviewed
CVE-2026-96287
was published
Oct 2, 2026
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity...
High
Unreviewed
CVE-2026-94655
was published
Oct 2, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue...
High
Unreviewed
CVE-2026-94658
was published
Oct 2, 2026
Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in...
High
Unreviewed
CVE-2026-96292
was published
Oct 2, 2026
Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings.
This issue...
High
Unreviewed
CVE-2026-94653
was published
Oct 2, 2026
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in...
High
Unreviewed
CVE-2026-104426
was published
Oct 2, 2026
Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name...
High
Unreviewed
CVE-2026-103604
was published
Oct 2, 2026
devalue: Residual sparse-array CPU amplification in uneval
Moderate
GHSA-hx4r-w6wj-j8fg
was published
for
devalue
(npm)
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API