Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

536 advisories

Loading
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint Low
CVE-2026-10177 was published for aider-chat (pip) May 31, 2026
Aider is vulnerable to Code Injection via editor_coder.run function Low
CVE-2026-10175 was published for aider-chat (pip) May 31, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key Low
CVE-2026-9712 was published for pretix (pip) May 27, 2026
hermes-agent has an Incorrect Comparison Low
CVE-2026-9369 was published for hermes-agent (pip) May 26, 2026
Crawlee for Python: SSRF via sitemap-derived URLs Low
CVE-2026-46497 was published for crawlee (pip) May 21, 2026
FORIMOC Credited to FORIMOC and Arturo0x90 Arturo0x90 Arturo0x90
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs Low
CVE-2026-45739 was published for strawberry-graphql (pip) May 19, 2026
lpschroer Credited to lpschroer, bellini666, and patrick91 bellini666 bellini666
patrick91 patrick91
qi-scape Credited to qi-scape and Classic298 Classic298 Classic298
OSGeo gdal has a heap-based buffer overflow Low
CVE-2026-8212 was published for GDAL (pip) May 10, 2026
justhtml introduces denial-of-service hardening Low
GHSA-r8cj-3554-33mr was published for justhtml (pip) May 8, 2026
EmilStenstrom Credited to EmilStenstrom
OSGeo GDAL vulnerable to out-of-bounds read Low
CVE-2026-8088 was published for GDAL (pip) May 7, 2026
OSGeo GDAL vulnerable to heap-based buffer overflow Low
CVE-2026-8087 was published for GDAL (pip) May 7, 2026
aiograpi has dependency on vulnerable orjson 3.11.4 (CVE-2025-67221) Low
GHSA-7mw3-79jq-xc7f was published for aiograpi (pip) May 6, 2026
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed Low
CVE-2026-42448 was published for magic-wormhole (pip) May 6, 2026
Paramiko rsakey.py allows the SHA-1 algorithm Low
CVE-2026-44405 was published for paramiko (pip) May 6, 2026
ciguard: Web UI is missing HTTP defence-in-depth headers Low
GHSA-7ww3-xvf5-cxwm was published for ciguard (pip) May 5, 2026
ciguard: discover_pipeline_files follows symlinks out of scan root Low
CVE-2026-44220 was published for ciguard (pip) May 5, 2026
ciguard: Container image runs as root (no USER directive) Low
CVE-2026-44218 was published for ciguard (pip) May 5, 2026
Microdot has HTTP response splitting in Response.set_cookie() Low
CVE-2026-42874 was published for microdot (pip) May 5, 2026
luantq0 Credited to luantq0
Langchain-Chatchat Uses Insufficiently Random Values Low
CVE-2026-7847 was published for langchain-chatchat (pip) May 5, 2026
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API Low
CVE-2026-7846 was published for langchain-chatchat (pip) May 5, 2026
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm Low
CVE-2026-7845 was published for langchain-chatchat (pip) May 5, 2026
Django Uses Cache Containing Sensitive Information Low
CVE-2026-6907 was published for Django (pip) May 5, 2026
ProTip! Advisories are also available from the GraphQL API