Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
js-yaml: Exponential parsing time in flow collections leads to denial of service High
CVE-2026-73643 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk) High
CVE-2026-33979 was published for express-xss-sanitizer (npm) Mar 27, 2026
lissy93 Credited to lissy93
ProTip! Advisories are also available from the GraphQL API