GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
303 advisories
Filter by severity
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
High
CVE-2026-53503
was published
for
thumbor
(pip)
Jul 31, 2026
vLLM has Remote DoS via Invalid Recovered Token Reinjection
High
CVE-2026-54234
was published
for
vllm
(pip)
Jul 17, 2026
vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models
Moderate
CVE-2026-34760
was published
for
vllm
(pip)
Jul 17, 2026
Pixeldrain API key shared with unverified thirdparty sites
Moderate
CVE-2026-54254
was published
for
cyberdrop-dl-patched
(pip)
Jul 15, 2026
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
High
CVE-2026-21887
was published
for
pycti
(pip)
Jun 22, 2026
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
Moderate
CVE-2026-54911
was published
for
ujson
(pip)
Jun 19, 2026
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
Low
CVE-2026-12566
was published
for
bbot
(pip)
Jun 18, 2026
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
High
CVE-2026-57143
was published
for
praisonaiagents
(pip)
Jun 18, 2026
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
High
CVE-2026-57130
was published
for
praisonaiagents
(pip)
Jun 18, 2026
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Low
CVE-2026-54282
was published
for
Starlette
(pip)
Jun 15, 2026
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
Low
CVE-2026-53537
was published
for
python-multipart
(pip)
Jun 15, 2026
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass
Critical
CVE-2026-44180
was published
for
jupyter_enterprise_gateway
(pip)
Jun 3, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Low
CVE-2026-10566
was published
for
metagpt
(pip)
Jun 2, 2026
eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
Moderate
GHSA-74r7-3mjm-jc5v
was published
for
edumfa
(pip)
May 18, 2026
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
High
GHSA-3wgj-c2hg-vm6q
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Moderate
CVE-2026-45317
was published
for
open-webui
(pip)
May 14, 2026
Synapse pagination Denial of Service
Moderate
CVE-2026-45076
was published
for
matrix-synapse
(pip)
May 14, 2026
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)
Moderate
GHSA-88q9-cmp2-c2vq
was published
for
OxidizePdf.NET
(NuGet)
May 11, 2026
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
Critical
CVE-2026-44336
was published
for
PraisonAI
(pip)
May 11, 2026
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
Moderate
CVE-2026-44337
was published
for
PraisonAI
(pip)
May 11, 2026
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
High
GHSA-mv93-w799-cj2w
was published
for
GitPython
(pip)
May 8, 2026
gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expense
High
GHSA-52cq-7v8r-62c6
was published
for
gmaps-mcp
(pip)
May 8, 2026
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
High
CVE-2026-42544
was published
for
granian
(pip)
May 6, 2026
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
High
CVE-2026-42266
was published
for
jupyterlab
(pip)
May 5, 2026
pyp2spec is Vulnerable to Code Injection
High
CVE-2026-42301
was published
for
pyp2spec
(pip)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API