GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,334
Maven
5,000+
npm
3,967
NuGet
713
pip
3,763
Pub
12
RubyGems
923
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
241 advisories
Filter by severity
vLLM vulnerable to Regular Expression Denial of Service
Moderate
GHSA-j828-28rj-hfhp
was published
for
vllm
(pip)
May 28, 2025
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
Moderate
CVE-2025-48887
was published
for
vllm
(pip)
May 28, 2025
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Moderate
CVE-2018-25110
was published
for
marked
(npm)
May 23, 2025
Hugging Face Transformers Regular Expression Denial of Service
Moderate
CVE-2025-2099
was published
for
transformers
(pip)
May 19, 2025
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
Moderate
CVE-2025-46560
was published
for
vllm
(pip)
Apr 29, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-1194
was published
for
transformers
(pip)
Apr 29, 2025
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
GHSA-hx7h-9vf7-5xhg
was published
for
uptime-kuma
(npm)
Mar 31, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2024-12720
was published
for
transformers
(pip)
Mar 20, 2025
H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
High
CVE-2024-10550
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Uptime Kuma ReDoS vulnerability
Moderate
CVE-2025-26042
was published
for
uptime-kuma
(npm)
Mar 17, 2025
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
Moderate
CVE-2025-27789
was published
for
@babel/helpers
(npm)
Mar 11, 2025
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Moderate
CVE-2025-27220
was published
for
cgi
(RubyGems)
Mar 3, 2025
@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25290
was published
for
@octokit/request
(npm)
Feb 14, 2025
@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25289
was published
for
@octokit/request-error
(npm)
Feb 14, 2025
@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25288
was published
for
@octokit/plugin-paginate-rest
(npm)
Feb 14, 2025
@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25285
was published
for
@octokit/endpoint
(npm)
Feb 14, 2025
parse-duration has a Regex Denial of Service that results in event loop delay and out of memory
High
CVE-2025-25283
was published
for
parse-duration
(npm)
Feb 12, 2025
Inefficient Regular Expression Complexity in koa
Critical
CVE-2025-25200
was published
for
koa
(npm)
Feb 12, 2025
parse-uri Regular expression Denial of Service (ReDoS)
Moderate
CVE-2024-36751
was published
for
parse-uri
(npm)
Jan 16, 2025
path-to-regexp contains a ReDoS
High
CVE-2024-52798
was published
for
path-to-regexp
(npm)
Dec 5, 2024
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
High
CVE-2024-10270
was published
for
org.keycloak:keycloak-services
(Maven)
Nov 25, 2024
Duplicate Advisory: org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
Moderate
GHSA-j3x3-r585-4qhg
was published
for
org.keycloak:keycloak-services
(Maven)
Nov 25, 2024
•
withdrawn
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
Low
CVE-2024-21539
was published
for
@eslint/plugin-kit
(npm)
Nov 15, 2024
ReDoS in giskard's transformation.py (GHSL-2024-324)
Moderate
CVE-2024-52524
was published
for
giskard
(pip)
Nov 14, 2024
ProTip!
Advisories are also available from the
GraphQL API