Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,349 advisories

Loading
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
EQSTLab Credited to EQSTLab
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials Moderate
CVE-2026-59222 was published for open-webui (pip) Jul 24, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, grumpinout1, and Classic298 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1 Classic298 Classic298
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
CVE-2026-73416 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
tablib: Stored XSS in the HTML export via unescaped dataset title Moderate
CVE-2026-9318 was published for tablib (pip) Aug 12, 2026
antonisloukis Credited to antonisloukis
apache-airflow DAG source authorization bypass exposes co-located DAG source Moderate
CVE-2026-49296 was published for apache-airflow (pip) Jul 7, 2026
0x00-sys Credited to 0x00-sys
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
pypdf: Possible large memory usage for large /ToUnicode streams Moderate
CVE-2026-71870 was published for pypdf (pip) Aug 7, 2026
idisdi Credited to idisdi and stefan6419846 stefan6419846 stefan6419846
Keras: HDF5 links can disclose local file contents Moderate
CVE-2026-9335 was published for keras (pip) Aug 2, 2026
Keras: HDF5 virtual datasets can disclose local files Moderate
CVE-2026-12480 was published for keras (pip) Jul 1, 2026
Keras: DiskIOStore permits path traversal through crafted layer names Moderate
CVE-2026-12479 was published for keras (pip) Jun 22, 2026
Django: GDALRaster may over-read heap memory when constructed from bytes Moderate
CVE-2026-53877 was published for django (pip) Jul 7, 2026
Django: DomainNameValidator permits newline characters that may enable HTTP header injection Moderate
CVE-2026-53878 was published for django (pip) Jul 7, 2026
OpenStack Neutron Improper Input Validation vulnerability Moderate
CVE-2015-3221 was published for neutron (pip) May 14, 2022
cardoe Credited to cardoe
pypdf: Possible long runtimes/large memory usage for large CID font width ranges Moderate
CVE-2026-71852 was published for pypdf (pip) Aug 7, 2026
7thParkk Credited to 7thParkk and stefan6419846 stefan6419846 stefan6419846
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
x41j Credited to x41j, ehhthing, and nic-lovin ehhthing ehhthing
nic-lovin nic-lovin
h2: Duplicate Host header could facilitate request smuggling Moderate
CVE-2026-71554 was published for h2 (pip) Aug 6, 2026
SunandM Credited to SunandM
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands Moderate
CVE-2026-18654 was published for awscli (pip) Aug 6, 2026
Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code Moderate
CVE-2025-55013 was published for assemblyline-service-client (pip) Jul 25, 2025
Open WebUI: DNS Rebinding SSRF Bypass Moderate
CVE-2026-54020 was published for open-webui (pip) Aug 4, 2026
rezaduty Credited to rezaduty, Classic298, dhyabi2, geo-chen, and bogdancherniy11-sudo Classic298 Classic298
dhyabi2 dhyabi2 geo-chen geo-chen bogdancherniy11-sudo bogdancherniy11-sudo
Classic298 Credited to Classic298
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints Moderate
CVE-2026-70491 was published for open-webui (pip) Aug 4, 2026
bogdancherniy11-sudo Credited to bogdancherniy11-sudo and Classic298 Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
ProTip! Advisories are also available from the GraphQL API