GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,967
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
143 advisories
Filter by severity
TCPDF vulnerable to Regular Expression Denial of Service
Moderate
CVE-2024-22640
was published
for
tecnickcom/tcpdf
(Composer)
Apr 19, 2024
Pydantic regular expression denial of service
Moderate
CVE-2024-3772
was published
for
pydantic
(pip)
Apr 15, 2024
A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6...
Moderate
Unreviewed
CVE-2023-6489
was published
Apr 12, 2024
An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions...
Moderate
Unreviewed
CVE-2023-6678
was published
Apr 12, 2024
Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
Moderate
CVE-2024-3651
was published
for
idna
(pip)
Apr 11, 2024
Black vulnerable to Regular Expression Denial of Service (ReDoS)
Moderate
CVE-2024-21503
was published
for
black
(pip)
Mar 19, 2024
Regular expression denial-of-service in Django
Moderate
CVE-2024-27351
was published
for
django
(pip)
Mar 15, 2024
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
Moderate
CVE-2024-25126
was published
for
rack
(RubyGems)
Feb 28, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7...
Moderate
Unreviewed
CVE-2023-6736
was published
Feb 8, 2024
nodemailer ReDoS when trying to send a specially crafted email
Moderate
GHSA-9h6g-pr28-7cqp
was published
for
nodemailer
(npm)
Jan 31, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16...
Moderate
Unreviewed
CVE-2023-6159
was published
Jan 26, 2024
@adobe/css-tools Improper Input Validation and Inefficient Regular Expression Complexity
Moderate
CVE-2023-48631
was published
for
@adobe/css-tools
(npm)
Nov 30, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16...
Moderate
Unreviewed
CVE-2023-3909
was published
Nov 6, 2023
TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link
Moderate
CVE-2023-45813
was published
for
torbot
(pip)
Oct 19, 2023
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5,...
Moderate
Unreviewed
CVE-2023-3205
was published
Sep 1, 2023
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5,...
Moderate
Unreviewed
CVE-2023-3210
was published
Sep 1, 2023
@adobe/css-tools Regular Expression Denial of Service (ReDOS) while Parsing CSS
Moderate
CVE-2023-26364
was published
for
@adobe/css-tools
(npm)
Aug 29, 2023
Issue summary: Checking excessively long DH keys or parameters may be very slow.
Impact summary:...
Moderate
Unreviewed
CVE-2023-3446
was published
Jul 19, 2023
URI gem has ReDoS vulnerability
Moderate
CVE-2023-36617
was published
for
uri
(RubyGems)
Jun 29, 2023
An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1,...
Moderate
Unreviewed
CVE-2023-2232
was published
Jun 28, 2023
word-wrap vulnerable to Regular Expression Denial of Service
Moderate
CVE-2023-26115
was published
for
word-wrap
(npm)
Jun 22, 2023
Liferay Portal has Inefficient Regular Expression
Moderate
CVE-2023-33950
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2...
Moderate
Unreviewed
CVE-2023-1894
was published
May 5, 2023
ProTip!
Advisories are also available from the
GraphQL API