Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,363 advisories

Loading
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation Moderate
CVE-2026-55236 was published for langgraph-api (pip) Aug 19, 2026
OneThing4101 Credited to OneThing4101
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication Moderate
CVE-2026-55235 was published for langgraph-api (pip) Aug 19, 2026
BedheadProgrammer Credited to BedheadProgrammer
manus-use Credited to manus-use
sour-exploit Credited to sour-exploit
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority Moderate
CVE-2026-71317 was published for lemur (pip) Aug 18, 2026
maperu Credited to maperu
devpi-server may leak database contents Moderate
CVE-2026-54723 was published for devpi-server (pip) Aug 18, 2026
pavelrevak Credited to pavelrevak
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads Moderate
CVE-2026-68922 was published for mobsf (pip) Aug 18, 2026
Daniel-GrunbergerCA Credited to Daniel-GrunbergerCA
MobSF's CSRF checks not enforced after Django migration Moderate
CVE-2026-68923 was published for mobsf (pip) Aug 18, 2026
ya3raj Credited to ya3raj
ya3raj Credited to ya3raj
Copyparty vulnerable to file/dirkey confusion Moderate
CVE-2026-70657 was published for copyparty (pip) Aug 18, 2026
poolcritter Credited to poolcritter
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config Moderate
CVE-2026-68520 was published for glances (pip) Aug 17, 2026
0xTodor Credited to 0xTodor
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes Moderate
CVE-2026-59894 was published for sqlparse (pip) Aug 17, 2026
7thParkk Credited to 7thParkk
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
EQSTLab Credited to EQSTLab
tablib: Stored XSS in the HTML export via unescaped dataset title Moderate
CVE-2026-9318 was published for tablib (pip) Aug 12, 2026
antonisloukis Credited to antonisloukis
pypdf: Possible large memory usage for large /ToUnicode streams Moderate
CVE-2026-71870 was published for pypdf (pip) Aug 7, 2026
idisdi Credited to idisdi and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes/large memory usage for large CID font width ranges Moderate
CVE-2026-71852 was published for pypdf (pip) Aug 7, 2026
7thParkk Credited to 7thParkk and stefan6419846 stefan6419846 stefan6419846
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
h2: Duplicate Host header could facilitate request smuggling Moderate
CVE-2026-71554 was published for h2 (pip) Aug 6, 2026
SunandM Credited to SunandM
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands Moderate
CVE-2026-18654 was published for awscli (pip) Aug 6, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
Classic298 Credited to Classic298
ProTip! Advisories are also available from the GraphQL API