Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

208 advisories

Loading
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path> High
CVE-2026-107378 was published for cairosvg (pip) Oct 8, 2026
mohammedix88 Credited to mohammedix88
Pydantic AI: Excessive resource use when local web fetching converts nested HTML Moderate
CVE-2026-107287 was published for pydantic-ai (pip) Oct 8, 2026
SounLabs Credited to SounLabs
msgpack5: Quadratic parsing in the streaming decoder Moderate
CVE-2026-107297 was published for msgpack5 (npm) Oct 8, 2026
SWIFI-AI Credited to SWIFI-AI
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` Moderate
CVE-2026-107290 was published for pydantic-ai (pip) Oct 8, 2026
BrianWillows Credited to BrianWillows
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line Moderate
GHSA-r4xh-jqrq-34v2 was published for smol-toml (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion Moderate
CVE-2026-104844 was published for postcss-selector-parser (npm) Oct 5, 2026
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk Moderate
CVE-2026-104182 was published for stream-json (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in... High Unreviewed
CVE-2026-104426 was published Oct 2, 2026
devalue: Residual sparse-array CPU amplification in uneval Moderate
GHSA-hx4r-w6wj-j8fg was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
ProTip! Advisories are also available from the GraphQL API