GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,363 advisories
Filter by severity
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
Moderate
CVE-2026-55236
was published
for
langgraph-api
(pip)
Aug 19, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Moderate
CVE-2026-55235
was published
for
langgraph-api
(pip)
Aug 19, 2026
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
Moderate
CVE-2026-73974
was published
for
linuxfabrik-lib
(pip)
Aug 18, 2026
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Moderate
CVE-2026-71322
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Moderate
CVE-2026-71317
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Moderate
CVE-2026-70667
was published
for
lemur
(pip)
Aug 18, 2026
devpi-server may leak database contents
Moderate
CVE-2026-54723
was published
for
devpi-server
(pip)
Aug 18, 2026
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
Moderate
CVE-2026-68922
was published
for
mobsf
(pip)
Aug 18, 2026
MobSF's CSRF checks not enforced after Django migration
Moderate
CVE-2026-68923
was published
for
mobsf
(pip)
Aug 18, 2026
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
Moderate
CVE-2026-68924
was published
for
mobsf
(pip)
Aug 18, 2026
Copyparty vulnerable to file/dirkey confusion
Moderate
CVE-2026-70657
was published
for
copyparty
(pip)
Aug 18, 2026
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Moderate
CVE-2026-68520
was published
for
glances
(pip)
Aug 17, 2026
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Moderate
CVE-2026-68517
was published
for
glances
(pip)
Aug 17, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Moderate
CVE-2026-53708
was published
for
mcp-contextforge-gateway
(pip)
Aug 14, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
tablib: Stored XSS in the HTML export via unescaped dataset title
Moderate
CVE-2026-9318
was published
for
tablib
(pip)
Aug 12, 2026
pypdf: Possible large memory usage for large /ToUnicode streams
Moderate
CVE-2026-71870
was published
for
pypdf
(pip)
Aug 7, 2026
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
Moderate
CVE-2026-71852
was published
for
pypdf
(pip)
Aug 7, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
GHSA-hh9p-6wh2-4mfc
was published
for
GitPython
(pip)
Aug 7, 2026
h2: Duplicate Host header could facilitate request smuggling
Moderate
CVE-2026-71554
was published
for
h2
(pip)
Aug 6, 2026
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
Moderate
CVE-2026-18654
was published
for
awscli
(pip)
Aug 6, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
Moderate
CVE-2026-71433
was published
for
langgraph-checkpoint-postgres
(pip)
Aug 6, 2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Moderate
CVE-2026-70493
was published
for
open-webui
(pip)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API