GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            12 advisories
        Filter by severity
        
      
      
    
                    
                      Regular Expression Denial of Service in debug
                    
                      
  Low
                    
                
                      
                        CVE-2017-16137
                      
                      was published
                        for
                        
                          debug
                        
                        (npm)
                      Aug 9, 2018 
                    
                  
                    
                      Regular Expression Denial of Service in jadedown
                    
                      
  Low
                    
                
                      
                        CVE-2016-10520
                      
                      was published
                        for
                        
                          jadedown
                        
                        (npm)
                      Feb 18, 2019 
                    
                  
                    
                      ircdkit vulnerable to Denial of Service due to unhandled connection end event
                    
                      
  Low
                    
                
                      
                        GHSA-f7r3-p866-q9qr
                      
                      was published
                        for
                        
                          ircdkit
                        
                        (npm)
                      Jun 3, 2019 
                    
                  
                    
                      Regular Expression Denial of Service in braces
                    
                      
  Low
                    
                
                      
                        GHSA-g95f-p29q-9xw4
                      
                      was published
                        for
                        
                          braces
                        
                        (npm)
                      Jun 6, 2019 
                    
                  
                    
                      Denial of Service in apostrophe
                    
                      
  Low
                    
                
                      
                        GHSA-pv6r-vchh-cxg9
                      
                      was published
                        for
                        
                          apostrophe
                        
                        (npm)
                      Sep 3, 2020 
                    
                  
                    
                      Regular Expression Denial of Service in markdown
                    
                      
  Low
                    
                
                      
                        GHSA-wx77-rp39-c6vg
                      
                      was published
                        for
                        
                          markdown
                        
                        (npm)
                      Sep 4, 2020 
                    
                  
                    
                      Denial of service in fast-csv
                    
                      
  Low
                    
                
                      
                        CVE-2020-26256
                      
                      was published
                        for
                        
                          @fast-csv/parse
                        
                        (npm)
                      Dec 8, 2020 
                    
                  
                    
                      Regex denial of service vulnerability in codesample plugin
                    
                      
  Low
                    
                
                      
                        GHSA-h96f-fc7c-9r55
                      
                      was published
                        for
                        
                          tinymce
                        
                        (npm)
                      Jan 6, 2021 
                    
                  
                    
                      Regular Expression Denial of Service (ReDoS) in jsx-slack
                    
                      
  Low
                    
                
                      
                        CVE-2021-43838
                      
                      was published
                        for
                        
                          jsx-slack
                        
                        (npm)
                      Dec 17, 2021 
                    
                  
                    
                      Regular Expression Denial of Service (ReDoS) in braces
                    
                      
  Low
                    
                
                      
                        CVE-2018-1109
                      
                      was published
                        for
                        
                          braces
                        
                        (npm)
                      Jan 6, 2022 
                    
                  
                    
                      pm2 Regular Expression Denial of Service vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-5891
                      
                      was published
                        for
                        
                          pm2
                        
                        (npm)
                      Jun 9, 2025 
                    
                  
                    
                      brace-expansion Regular Expression Denial of Service vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-5889
                      
                      was published
                        for
                        
                          brace-expansion
                        
                        (npm)
                      Jun 9, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API