GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
23 advisories
Filter by severity
Next.js: Denial of Service in the Image Optimization API using SVGs
Moderate
CVE-2026-64644
was published
for
next
(npm)
Jul 22, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption in js-yaml
Moderate
CVE-2026-59868
was published
for
js-yaml
(npm)
Jul 20, 2026
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
Moderate
CVE-2026-59870
was published
for
js-yaml
(npm)
Jul 20, 2026
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
Moderate
CVE-2026-48516
was published
for
MessagePack
(NuGet)
Jun 25, 2026
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
Moderate
CVE-2026-48511
was published
for
MessagePack
(NuGet)
Jun 25, 2026
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
Moderate
CVE-2026-55206
was published
for
py7zr
(pip)
Jun 19, 2026
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
Moderate
CVE-2026-49460
was published
for
pypdf
(pip)
Jun 16, 2026
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
Moderate
CVE-2026-48988
was published
for
markdown-it
(npm)
Jun 15, 2026
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
Moderate
CVE-2026-53550
was published
for
js-yaml
(npm)
Jun 15, 2026
ImageMagick: Policy Bypass in MNG coder could
Moderate
CVE-2026-45664
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
May 18, 2026
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
Moderate
GHSA-q2qq-hmj6-3wpp
was published
for
hickory-proto
(Rust)
May 7, 2026
graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
Moderate
CVE-2026-40476
was published
for
webonyx/graphql-php
(Composer)
Apr 14, 2026
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler
Moderate
CVE-2026-35599
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Django has potential DoS via MultiPartParser through crafted multipart uploads
Moderate
CVE-2026-33033
was published
for
Django
(pip)
Apr 7, 2026
pypdf has inefficient decoding of array-based streams
Moderate
CVE-2026-33123
was published
for
pypdf
(pip)
Mar 18, 2026
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
Moderate
CVE-2026-28804
was published
for
pypdf
(pip)
Mar 2, 2026
golang.org/x/net/html has a Quadratic Parsing Complexity issue
Moderate
CVE-2025-47911
was published
for
golang.org/x/net/html
(Go)
Feb 12, 2026
Django is vulnerable to DoS via XML serializer text extraction
Moderate
CVE-2025-64460
was published
for
Django
(pip)
Dec 2, 2025
Netty QUIC hash collision DoS attack
Moderate
CVE-2025-29908
was published
for
io.netty.incubator:netty-incubator-codec-quic
(Maven)
Mar 31, 2025
Kwik hash collision vulnerability
Moderate
CVE-2025-23020
was published
for
tech.kwik:kwik
(Maven)
Feb 20, 2025
Several quadratic complexity bugs may lead to denial of service in Commonmarker
Moderate
GHSA-7vh7-fw88-wj87
was published
for
commonmarker
(RubyGems)
Aug 8, 2023
PyPDF2 quadratic runtime with malformed PDF missing xref marker
Moderate
CVE-2023-36810
was published
for
PyPDF2
(pip)
Jun 30, 2023
Inefficient Algorithmic Complexity in Apache Santuario XML Security
Moderate
CVE-2013-2172
was published
for
org.apache.santuario:xmlsec
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API