Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

303 advisories

Loading
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS High
CVE-2026-53503 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
vLLM has Remote DoS via Invalid Recovered Token Reinjection High
CVE-2026-54234 was published for vllm (pip) Jul 17, 2026
NeilAlfred Credited to NeilAlfred and jperezdealgaba jperezdealgaba jperezdealgaba
kexinoh Credited to kexinoh, russellb, DarkLight1337, and Isotr0py russellb russellb
DarkLight1337 DarkLight1337 Isotr0py Isotr0py
Pixeldrain API key shared with unverified thirdparty sites Moderate
CVE-2026-54254 was published for cyberdrop-dl-patched (pip) Jul 15, 2026
NTFSvolume Credited to NTFSvolume
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature High
CVE-2026-21887 was published for pycti (pip) Jun 22, 2026
DaffySpider Credited to DaffySpider and TristanInSec TristanInSec TristanInSec
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps() Moderate
CVE-2026-54911 was published for ujson (pip) Jun 19, 2026
Zwique Credited to Zwique, bwoodsend, and hugovk bwoodsend bwoodsend
hugovk hugovk
sondt99 Credited to sondt99
Nx7n Credited to Nx7n
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters High
CVE-2026-57130 was published for praisonaiagents (pip) Jun 18, 2026
sondt99 Credited to sondt99
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname Low
CVE-2026-54282 was published for Starlette (pip) Jun 15, 2026
nic-lovin Credited to nic-lovin
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters Low
CVE-2026-53537 was published for python-multipart (pip) Jun 15, 2026
0xkakash1 Credited to 0xkakash1 and sammiee5311 sammiee5311 sammiee5311
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass Critical
CVE-2026-44180 was published for jupyter_enterprise_gateway (pip) Jun 3, 2026
ben-elttam Credited to ben-elttam, matt-elttam, daniel-elttam, and lresende matt-elttam matt-elttam
daniel-elttam daniel-elttam lresende lresende
eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check Moderate
GHSA-74r7-3mjm-jc5v was published for edumfa (pip) May 18, 2026
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url High
GHSA-3wgj-c2hg-vm6q was published for open-webui (pip) May 14, 2026
matte1782 Credited to matte1782
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation Moderate
CVE-2026-45317 was published for open-webui (pip) May 14, 2026
bray-sec Credited to bray-sec and Classic298 Classic298 Classic298
Synapse pagination Denial of Service Moderate
CVE-2026-45076 was published for matrix-synapse (pip) May 14, 2026
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS) Moderate
GHSA-88q9-cmp2-c2vq was published for OxidizePdf.NET (NuGet) May 11, 2026
bzsanti Credited to bzsanti
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection Critical
CVE-2026-44336 was published for PraisonAI (pip) May 11, 2026
amwhoi Credited to amwhoi
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries Moderate
CVE-2026-44337 was published for PraisonAI (pip) May 11, 2026
shmulc8 Credited to shmulc8
aslein1413-sys Credited to aslein1413-sys
gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expense High
GHSA-52cq-7v8r-62c6 was published for gmaps-mcp (pip) May 8, 2026
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic High
CVE-2026-42544 was published for granian (pip) May 6, 2026
Z-Bra0 Credited to Z-Bra0
pmcao Credited to pmcao, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
pyp2spec is Vulnerable to Code Injection High
CVE-2026-42301 was published for pyp2spec (pip) May 4, 2026
gouldnicholas Credited to gouldnicholas
ProTip! Advisories are also available from the GraphQL API