Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

479 advisories

Loading
Masofgon Credited to Masofgon
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing High
GHSA-j95f-988m-3j2f was published for @tiptap/core (npm) Sep 8, 2026
joostgrunwald Credited to joostgrunwald
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser High
CVE-2026-83619 was published for @xmldom/xmldom (npm) Sep 8, 2026
karfau Credited to karfau
Colord: Slow rejection of oversized malformed color strings Moderate
CVE-2026-85062 was published for colord (npm) Sep 8, 2026
GAP-dev Credited to GAP-dev
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions High
CVE-2026-83606 was published for @xmldom/xmldom (npm) Sep 8, 2026
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks Moderate
CVE-2026-81725 was published for nltk (pip) Sep 8, 2026
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
CVE-2026-80206 was published for nltk (pip) Sep 8, 2026
infycore Credited to infycore, ekaf, and agent-kira ekaf ekaf
agent-kira agent-kira
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
CVE-2026-80205 was published for nltk (pip) Sep 8, 2026
infycore Credited to infycore, ekaf, and agent-kira ekaf ekaf
agent-kira agent-kira
CyberKareem Credited to CyberKareem and jperezdealgaba jperezdealgaba jperezdealgaba
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
GHSA-vf76-f5cp-9846 was published for nltk (pip) Aug 31, 2026 withdrawn
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS High
CVE-2026-57584 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
Duplicate Advisory: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions High
GHSA-2rrw-hpqm-36pv was published for nltk (pip) Aug 26, 2026 withdrawn
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking High
GHSA-5jhf-fpp7-v2pv was published for nokogiri (RubyGems) Aug 25, 2026 withdrawn
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking High
CVE-2026-72818 was published for nltk (pip) Aug 21, 2026
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
tonghuaroot Credited to tonghuaroot
ProTip! Advisories are also available from the GraphQL API