GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,081 advisories
Filter by severity
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
Moderate
GHSA-x287-5c68-36wp
was published
for
openwisp-ipam
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Moderate
CVE-2026-54338
was published
for
jupyterhub
(pip)
Aug 25, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Critical
CVE-2026-45018
was published
for
chainlit
(pip)
Aug 25, 2026
Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
GHSA-3h2g-j4wp-7qqq
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
eml_parser vulnerable to DoS via deeply nested parens in Received headers
High
CVE-2026-55620
was published
for
eml_parser
(pip)
Aug 25, 2026
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
Moderate
CVE-2026-55619
was published
for
eml_parser
(pip)
Aug 25, 2026
eml_parser has a URL extraction bypass via HTML entities in URLs
Moderate
CVE-2026-55618
was published
for
eml_parser
(pip)
Aug 25, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
Moderate
CVE-2026-55419
was published
for
reachy-mini
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
High
CVE-2026-55571
was published
for
djust
(pip)
Aug 25, 2026
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
Critical
CVE-2026-55640
was published
for
nextcloud-mcp-server
(pip)
Aug 25, 2026
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
High
GHSA-8cp3-qxj6-px34
was published
for
utcp-http
(pip)
Aug 25, 2026
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
Moderate
CVE-2026-12210
was published
for
utcp-gql
(pip)
Aug 25, 2026
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
High
GHSA-9qhg-99ww-9mqc
was published
for
utcp-http
(pip)
Aug 25, 2026
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Critical
CVE-2026-55546
was published
for
qwed-mcp
(pip)
Aug 25, 2026
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
Critical
CVE-2026-55536
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
High
CVE-2026-55532
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
High
CVE-2026-55533
was published
for
PraisonAI
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API