GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
536 advisories
Filter by severity
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
Low
CVE-2026-10177
was published
for
aider-chat
(pip)
May 31, 2026
Aider is vulnerable to Code Injection via editor_coder.run function
Low
CVE-2026-10175
was published
for
aider-chat
(pip)
May 31, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
Low
CVE-2026-9712
was published
for
pretix
(pip)
May 27, 2026
hermes-agent has an Incorrect Comparison
Low
CVE-2026-9369
was published
for
hermes-agent
(pip)
May 26, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Low
CVE-2026-45739
was published
for
strawberry-graphql
(pip)
May 19, 2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Low
CVE-2026-8754
was published
for
AstrBot
(pip)
May 17, 2026
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Low
CVE-2026-45316
was published
for
open-webui
(pip)
May 14, 2026
dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
Low
CVE-2026-44970
was published
for
dbt-mcp
(pip)
May 14, 2026
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
Low
CVE-2026-44969
was published
for
dbt-mcp
(pip)
May 14, 2026
OSGeo gdal has a heap-based buffer overflow
Low
CVE-2026-8212
was published
for
GDAL
(pip)
May 10, 2026
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
OSGeo GDAL vulnerable to out-of-bounds read
Low
CVE-2026-8088
was published
for
GDAL
(pip)
May 7, 2026
OSGeo GDAL vulnerable to heap-based buffer overflow
Low
CVE-2026-8087
was published
for
GDAL
(pip)
May 7, 2026
aiograpi has dependency on vulnerable orjson 3.11.4 (CVE-2025-67221)
Low
GHSA-7mw3-79jq-xc7f
was published
for
aiograpi
(pip)
May 6, 2026
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Low
CVE-2026-42448
was published
for
magic-wormhole
(pip)
May 6, 2026
Paramiko rsakey.py allows the SHA-1 algorithm
Low
CVE-2026-44405
was published
for
paramiko
(pip)
May 6, 2026
ciguard: Web UI is missing HTTP defence-in-depth headers
Low
GHSA-7ww3-xvf5-cxwm
was published
for
ciguard
(pip)
May 5, 2026
ciguard: discover_pipeline_files follows symlinks out of scan root
Low
CVE-2026-44220
was published
for
ciguard
(pip)
May 5, 2026
ciguard: Container image runs as root (no USER directive)
Low
CVE-2026-44218
was published
for
ciguard
(pip)
May 5, 2026
Microdot has HTTP response splitting in Response.set_cookie()
Low
CVE-2026-42874
was published
for
microdot
(pip)
May 5, 2026
Langchain-Chatchat Uses Insufficiently Random Values
Low
CVE-2026-7847
was published
for
langchain-chatchat
(pip)
May 5, 2026
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
Low
CVE-2026-7846
was published
for
langchain-chatchat
(pip)
May 5, 2026
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
Low
CVE-2026-7845
was published
for
langchain-chatchat
(pip)
May 5, 2026
Django Uses Cache Containing Sensitive Information
Low
CVE-2026-6907
was published
for
Django
(pip)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API