Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,081 advisories

Loading
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
dizconnectz Credited to dizconnectz and nemesifier nemesifier nemesifier
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
muslimbek-0x Credited to muslimbek-0x
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login Moderate
CVE-2026-54338 was published for jupyterhub (pip) Aug 25, 2026
mauriceng98 Credited to mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk Zyy0530 Zyy0530
Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
eml_parser vulnerable to DoS via deeply nested parens in Received headers High
CVE-2026-55620 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
eml_parser has parser DoS via deeply nested parentheses in e-mail headers Moderate
CVE-2026-55619 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
eml_parser has a URL extraction bypass via HTML entities in URLs Moderate
CVE-2026-55618 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
reachy_mini Allows Unrestricted Upload of File with Dangerous Type Moderate
CVE-2026-55419 was published for reachy-mini (pip) Aug 25, 2026
nnfrog Credited to nnfrog and yuvalmo-jfrog yuvalmo-jfrog yuvalmo-jfrog
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` High
CVE-2026-55585 was published for qwed (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab
fortress07 Credited to fortress07
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion High
GHSA-8cp3-qxj6-px34 was published for utcp-http (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins Moderate
CVE-2026-12210 was published for utcp-gql (pip) Aug 25, 2026
hariantara Credited to hariantara
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target High
GHSA-9qhg-99ww-9mqc was published for utcp-http (pip) Aug 25, 2026
lexdotdev Credited to lexdotdev
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
ProTip! Advisories are also available from the GraphQL API