Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,932 advisories

Loading
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
athuljayaram Credited to athuljayaram
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read High
GHSA-rm43-82j9-r4mj was published for atomic-agents-stack (pip) Aug 13, 2026
EQSTLab Credited to EQSTLab
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) High
CVE-2026-55074 was published for ansible-jailexec (pip) Aug 12, 2026
Marsam2489 Credited to Marsam2489
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High
CVE-2026-52776 was published for compliance-trestle (pip) Aug 12, 2026
tonghuaroot Credited to tonghuaroot
tablib: Stored XSS in the HTML export via unescaped dataset title Moderate
CVE-2026-9318 was published for tablib (pip) Aug 12, 2026
antonisloukis Credited to antonisloukis
pypdf: Possible large memory usage for large /ToUnicode streams Moderate
CVE-2026-71870 was published for pypdf (pip) Aug 7, 2026
idisdi Credited to idisdi and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes/large memory usage for large CID font width ranges Moderate
CVE-2026-71852 was published for pypdf (pip) Aug 7, 2026
7thParkk Credited to 7thParkk and stefan6419846 stefan6419846 stefan6419846
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
manus-use Credited to manus-use
manus-use Credited to manus-use
tinyb0y Credited to tinyb0y
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
h2: Duplicate Host header could facilitate request smuggling Moderate
CVE-2026-71554 was published for h2 (pip) Aug 6, 2026
SunandM Credited to SunandM
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands Moderate
CVE-2026-18654 was published for awscli (pip) Aug 6, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
legobattman Credited to legobattman and Classic298 Classic298 Classic298
Classic298 Credited to Classic298
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages High
CVE-2026-70492 was published for open-webui (pip) Aug 4, 2026
maxntv Credited to maxntv and Classic298 Classic298 Classic298
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints Moderate
CVE-2026-70491 was published for open-webui (pip) Aug 4, 2026
bogdancherniy11-sudo Credited to bogdancherniy11-sudo and Classic298 Classic298 Classic298
ProTip! Advisories are also available from the GraphQL API