GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
762 advisories
Filter by severity
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
CVE-2026-79675
was published
for
nltk
(pip)
Sep 1, 2026
plone.app.event vulnerable to denial of service via iCalendar import
Critical
CVE-2026-55247
was published
for
plone.app.event
(pip)
Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet
Critical
CVE-2026-55248
was published
for
plone.app.portlets
(pip)
Aug 28, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Critical
CVE-2026-45018
was published
for
chainlit
(pip)
Aug 25, 2026
Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
GHSA-3h2g-j4wp-7qqq
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
Critical
CVE-2026-55640
was published
for
nextcloud-mcp-server
(pip)
Aug 25, 2026
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
Critical
CVE-2026-55546
was published
for
qwed-mcp
(pip)
Aug 25, 2026
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
Critical
CVE-2026-55536
was published
for
PraisonAI
(pip)
Aug 25, 2026
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
surfio has an out-of-bounds read
Critical
CVE-2026-55211
was published
for
surfio
(pip)
Aug 18, 2026
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Critical
CVE-2026-64849
was published
for
mlflow
(pip)
Aug 17, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Critical
CVE-2026-67429
was published
for
flyto-core
(pip)
Jul 30, 2026
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Critical
CVE-2026-64825
was published
for
homeassistant
(pip)
Jul 21, 2026
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
Critical
CVE-2026-61736
was published
for
lightrag-hku
(pip)
Jul 20, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
CVE-2026-15925
was published
for
snowflake-connector-python
(pip)
Jul 16, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Critical
CVE-2026-61667
was published
for
DIRAC
(pip)
Jul 13, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Critical
CVE-2026-45579
was published
for
DIRAC
(pip)
Jul 13, 2026
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
Critical
CVE-2026-61459
was published
for
mcp-server-kubernetes
(pip)
Jul 10, 2026
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Critical
CVE-2026-55615
was published
for
langroid
(pip)
Jul 6, 2026
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Critical
CVE-2026-54769
was published
for
langroid
(pip)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API