Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

260 advisories

Loading
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
Wagtail: Denial of service via unbounded filter specs in the image preview Moderate
CVE-2026-54260 was published for wagtail (pip) Aug 20, 2026
zerolab Credited to zerolab and 0x1saac 0x1saac 0x1saac
ya3raj Credited to ya3raj
sqlparse: Quadratic O(n²) DoS in group_comments High
CVE-2026-71491 was published for sqlparse (pip) Aug 17, 2026
sanktjodel Credited to sanktjodel and mohammedix88 mohammedix88 mohammedix88
pyasn1 has a DoS vulnerability in decoder High
CVE-2026-23490 was published for pyasn1 (pip) Jan 16, 2026
tsigouris007 Credited to tsigouris007
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
libp2p: yamux connection DoS via oversized data frame High
CVE-2026-73568 was published for libp2p (pip) Jul 24, 2026
tahaafarooq Credited to tahaafarooq
pypdf: Possible large memory usage for large /ToUnicode streams Moderate
CVE-2026-71870 was published for pypdf (pip) Aug 7, 2026
idisdi Credited to idisdi and stefan6419846 stefan6419846 stefan6419846
7p9eiiwqo8kos Credited to 7p9eiiwqo8kos
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Moderate
CVE-2026-70489 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building High
CVE-2026-69249 was published for cryptography (pip) Aug 3, 2026
sjudson Credited to sjudson and woodruffw woodruffw woodruffw
agners Credited to agners and bdraco bdraco bdraco
Docling: Unsafe URI and Path Handling in HTML Backend High
CVE-2026-47214 was published for docling (pip) Jun 3, 2026
AnistoMejin Credited to AnistoMejin and brodmart brodmart brodmart
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs High
CVE-2026-59884 was published for pyasn1 (pip) Jul 21, 2026
mikeappsec Credited to mikeappsec, HsiangNianian, and westonsteimel HsiangNianian HsiangNianian
westonsteimel westonsteimel
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS High
CVE-2026-53505 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter High
CVE-2026-53504 was published for thumbor (pip) Jul 31, 2026
geraldino2 Credited to geraldino2
hermes-agent has an Uncontrolled Resource Consumption issue Moderate
CVE-2026-10224 was published for hermes-agent (pip) Jun 1, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes for repeated malformed cross-reference entries Moderate
CVE-2026-59937 was published for pypdf (pip) Jul 23, 2026
akahane0x46 Credited to akahane0x46 and stefan6419846 stefan6419846 stefan6419846
pyasn1: Uncontrolled resource consumption when converting decoded REAL values High
CVE-2026-59886 was published for pyasn1 (pip) Jul 21, 2026
gvozdila Credited to gvozdila
tynus2 Credited to tynus2
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() High
CVE-2026-59200 was published for Pillow (pip) Jul 20, 2026
redyank Credited to redyank
ProTip! Advisories are also available from the GraphQL API