GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
76 advisories
Filter by severity
prismjs Regular Expression Denial of Service vulnerability
Moderate
CVE-2021-3801
was published
for
prismjs
(npm)
Sep 20, 2021
Uncontrolled Resource Consumption in trim-off-newlines
Moderate
CVE-2021-23425
was published
for
trim-off-newlines
(npm)
Sep 2, 2021
Uncontrolled Resource Consumption in transpile
Moderate
CVE-2021-23429
was published
for
transpile
(npm)
Sep 2, 2021
Unlimited transforms allowed for signed nodes
Moderate
CVE-2021-39171
was published
for
passport-saml
(npm)
Aug 30, 2021
Regular Expression Denial of Service in path-parse
Moderate
CVE-2021-23343
was published
for
path-parse
(npm)
Aug 10, 2021
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32012
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Denial of Service in SheetsJS Pro
Moderate
CVE-2021-32013
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32014
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Regular expression denial of service in forms
Moderate
CVE-2021-23388
was published
for
forms
(npm)
Jun 7, 2021
ReDoS in Sec-Websocket-Protocol header
Moderate
CVE-2021-32640
was published
for
ws
(npm)
May 28, 2021
Regular Expression Denial of Service in browserslist
Moderate
CVE-2021-23364
was published
for
browserslist
(npm)
May 24, 2021
Uncontrolled Resource Consumption in firebase
Moderate
CVE-2020-7765
was published
for
@firebase/util
(npm)
May 18, 2021
Regular expression deinal of service in express-validators
Moderate
CVE-2020-7767
was published
for
express-validators
(npm)
May 10, 2021
Regular expression denial of service in @absolunet/kafe
Moderate
CVE-2020-7761
was published
for
@absolunet/kafe
(npm)
May 10, 2021
Regular expression denial of service in codemirror
Moderate
CVE-2020-7760
was published
for
codemirror
(npm)
May 10, 2021
Regular Expression Denial of Service in postcss
Moderate
CVE-2021-23368
was published
for
postcss
(npm)
May 10, 2021
Uncontrolled Resource Consumption in fastify-multipart
Moderate
CVE-2020-8136
was published
for
fastify-multipart
(npm)
May 6, 2021
Regular Expression Denial of Service in hosted-git-info
Moderate
CVE-2021-23362
was published
for
hosted-git-info
(npm)
May 6, 2021
Uncontrolled Resource Consumption in rdf-graph-array
Moderate
CVE-2019-10798
was published
for
rdf-graph-array
(npm)
Apr 13, 2021
Regular Expression Denial of Service (ReDoS) in es6-crawler-detect
Moderate
CVE-2020-28501
was published
for
es6-crawler-detect
(npm)
Apr 13, 2021
Regular expression Denial of Service in multiple packages
Moderate
CVE-2021-21391
was published
for
@ckeditor/ckeditor5-engine
(npm)
Apr 6, 2021
html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)
Moderate
CVE-2021-23346
was published
for
html-parse-stringify
(npm)
Mar 18, 2021
Regular expression Denial of Service in @progfay/scrapbox-parser
Moderate
CVE-2021-27405
was published
for
@progfay/scrapbox-parser
(npm)
Mar 1, 2021
Regular Expression Denial of Service (REDoS) in Marked
Moderate
CVE-2021-21306
was published
for
marked
(npm)
Feb 8, 2021
CKEditor 5 Markdown plugin Regular expression Denial of Service
Moderate
CVE-2021-21254
was published
for
@ckeditor/ckeditor5-markdown-gfm
(npm)
Jan 29, 2021
ProTip!
Advisories are also available from the
GraphQL API