GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,349 advisories
Filter by severity
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Moderate
CVE-2026-59222
was published
for
open-webui
(pip)
Jul 24, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
CVE-2026-73416
was published
for
jupyterlab
(pip)
Jul 22, 2026
tablib: Stored XSS in the HTML export via unescaped dataset title
Moderate
CVE-2026-9318
was published
for
tablib
(pip)
Aug 12, 2026
apache-airflow DAG source authorization bypass exposes co-located DAG source
Moderate
CVE-2026-49296
was published
for
apache-airflow
(pip)
Jul 7, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
Moderate
CVE-2026-71433
was published
for
langgraph-checkpoint-postgres
(pip)
Aug 6, 2026
pypdf: Possible large memory usage for large /ToUnicode streams
Moderate
CVE-2026-71870
was published
for
pypdf
(pip)
Aug 7, 2026
Keras: HDF5 links can disclose local file contents
Moderate
CVE-2026-9335
was published
for
keras
(pip)
Aug 2, 2026
Keras: HDF5 virtual datasets can disclose local files
Moderate
CVE-2026-12480
was published
for
keras
(pip)
Jul 1, 2026
Keras: DiskIOStore permits path traversal through crafted layer names
Moderate
CVE-2026-12479
was published
for
keras
(pip)
Jun 22, 2026
Django: GDALRaster may over-read heap memory when constructed from bytes
Moderate
CVE-2026-53877
was published
for
django
(pip)
Jul 7, 2026
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
Moderate
CVE-2026-53878
was published
for
django
(pip)
Jul 7, 2026
OpenStack Neutron Improper Input Validation vulnerability
Moderate
CVE-2015-3221
was published
for
neutron
(pip)
May 14, 2022
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
Moderate
CVE-2026-71852
was published
for
pypdf
(pip)
Aug 7, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
GHSA-hh9p-6wh2-4mfc
was published
for
GitPython
(pip)
Aug 7, 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Moderate
CVE-2026-48710
was published
for
starlette
(pip)
Jun 4, 2026
h2: Duplicate Host header could facilitate request smuggling
Moderate
CVE-2026-71554
was published
for
h2
(pip)
Aug 6, 2026
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
Moderate
CVE-2026-18654
was published
for
awscli
(pip)
Aug 6, 2026
Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
Moderate
CVE-2025-55013
was published
for
assemblyline-service-client
(pip)
Jul 25, 2025
Open WebUI: DNS Rebinding SSRF Bypass
Moderate
CVE-2026-54020
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Moderate
CVE-2026-70493
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Moderate
CVE-2026-70491
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API