GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
136 advisories
Filter by severity
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Moderate
CVE-2025-43764
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Aug 23, 2025
A regular expression used by AngularJS' linky https://docs.angularjs.org/api/ngSanitize/filter...
Moderate
Unreviewed
CVE-2025-4690
was published
Aug 19, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1...
Moderate
Unreviewed
CVE-2025-2937
was published
Aug 13, 2025
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-5197
was published
for
transformers
(pip)
Aug 6, 2025
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Moderate
CVE-2025-3933
was published
for
transformers
(pip)
Jul 11, 2025
fastapi-guard is vulnerable to ReDoS through inefficient regex
Moderate
CVE-2025-53539
was published
for
fastapi-guard
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its get_imports() function
Moderate
CVE-2025-3264
was published
for
transformers
(pip)
Jul 7, 2025
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
Moderate
CVE-2025-3263
was published
for
transformers
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Moderate
CVE-2025-3262
was published
for
transformers
(pip)
Jul 7, 2025
Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a...
Moderate
Unreviewed
CVE-2025-43880
was published
Jun 25, 2025
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions...
Moderate
Unreviewed
CVE-2024-4025
was published
Jun 20, 2025
PowSyBl Core contains Polynomial REDoS’es
Moderate
CVE-2025-48058
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain...
Moderate
Unreviewed
CVE-2025-6069
was published
Jun 17, 2025
taro-css-to-react-native Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5896
was published
for
taro-css-to-react-native
(npm)
Jun 9, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects...
Moderate
Unreviewed
CVE-2025-5895
was published
Jun 9, 2025
A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1....
Moderate
Unreviewed
CVE-2025-5892
was published
Jun 9, 2025
vLLM vulnerable to Regular Expression Denial of Service
Moderate
GHSA-j828-28rj-hfhp
was published
for
vllm
(pip)
May 28, 2025
vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`
Moderate
CVE-2025-48887
was published
for
vllm
(pip)
May 28, 2025
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Moderate
CVE-2018-25110
was published
for
marked
(npm)
May 23, 2025
Hugging Face Transformers Regular Expression Denial of Service
Moderate
CVE-2025-2099
was published
for
transformers
(pip)
May 19, 2025
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
Moderate
CVE-2025-46560
was published
for
vllm
(pip)
Apr 29, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-1194
was published
for
transformers
(pip)
Apr 29, 2025
The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin...
Moderate
Unreviewed
CVE-2024-13896
was published
Apr 10, 2025
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-26042
was published
for
uptime-kuma
(npm)
Mar 31, 2025
ProTip!
Advisories are also available from the
GraphQL API