Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py) High
CVE-2026-45338 was published for open-webui (pip) May 14, 2026
Sebasteuo Credited to Sebasteuo and Classic298 Classic298 Classic298
eml_parser has recursion DoS via nested message/rfc822 attachments Moderate
CVE-2026-44844 was published for eml_parser (pip) May 8, 2026
Sebasteuo Credited to Sebasteuo
hashi-vault-js has a path traversal and query parameter injection High
CVE-2026-55100 was published for hashi-vault-js (npm) Jul 31, 2026
Sebasteuo Credited to Sebasteuo
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
eml_parser has a URL extraction bypass via HTML entities in URLs Moderate
CVE-2026-55618 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
eml_parser has parser DoS via deeply nested parentheses in e-mail headers Moderate
CVE-2026-55619 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
eml_parser vulnerable to DoS via deeply nested parens in Received headers High
CVE-2026-55620 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
ProTip! Advisories are also available from the GraphQL API