GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,134
Maven
5,000+
npm
5,000+
NuGet
1,013
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,419
Swift
61
Unreviewed advisories
All unreviewed
5,000+
45 advisories
Filter by severity
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an...
Low
Unreviewed
CVE-2026-41848
was published
Jun 9, 2026
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Low
CVE-2026-45756
was published
for
symfony/json-path
(Composer)
May 28, 2026
Symfony's YAML Parser has a ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
Low
CVE-2026-45305
was published
for
symfony/symfony
(Composer)
May 27, 2026
Symfony hardened the parser when handling untrusted input
Low
CVE-2026-45133
was published
for
symfony/symfony
(Composer)
May 27, 2026
Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check
Low
CVE-2026-40319
was published
for
giskard-checks
(pip)
Apr 14, 2026
A flaw was found in libssh. A remote attacker, by controlling client configuration files or...
Low
Unreviewed
CVE-2026-0967
was published
Mar 26, 2026
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
Low
CVE-2026-4539
was published
for
Pygments
(pip)
Mar 22, 2026
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
Low
CVE-2026-24001
was published
for
diff
(npm)
Jan 14, 2026
pypdf has possible long runtimes for malformed startxref
Low
CVE-2026-22691
was published
for
pypdf
(pip)
Jan 9, 2026
PyMdown Extensions has a ReDOS bug in its Figure Capture extension
Low
CVE-2025-68142
was published
for
pymdown-extensions
(pip)
Dec 16, 2025
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
Low
CVE-2025-61581
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Oct 16, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
CVE-2025-61921
was published
for
sinatra
(RubyGems)
Oct 10, 2025
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54364
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54363
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser
Low
GHSA-xffm-g5w8-qvg7
was published
for
@eslint/plugin-kit
(npm)
Jul 18, 2025
string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)
Low
CVE-2025-45143
was published
for
string-math
(npm)
Jun 30, 2025
PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion
Low
CVE-2025-48059
was published
for
com.powsybl:powsybl-contingency-api
(Maven)
Jun 19, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as...
Low
Unreviewed
CVE-2025-4215
was published
May 2, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
Low
CVE-2024-21539
was published
for
@eslint/plugin-kit
(npm)
Nov 15, 2024
ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
Low
CVE-2024-9506
was published
for
vue
(npm)
Oct 15, 2024
A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and...
Low
Unreviewed
CVE-2023-7279
was published
Sep 2, 2024
The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial...
Low
Unreviewed
CVE-2024-6434
was published
Jul 4, 2024
[TagAwareCipher] - Decryption Failure (Regex Match)
Low
CVE-2024-28864
was published
for
ilicmiljan/secure-props
(Composer)
Mar 18, 2024
ProTip!
Advisories are also available from the
GraphQL API