Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,376 advisories

Loading
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
prasanna8585 Credited to prasanna8585
RestrictedPython guard hooks can be shadowed via positional-only arguments High
CVE-2026-55830 was published for RestrictedPython (pip) Aug 28, 2026
Neroli-realy Credited to Neroli-realy, dataflake, and taisehub dataflake dataflake
taisehub taisehub
H3xV0rT3x Credited to H3xV0rT3x, nijel, and EndlssNightmare nijel nijel
EndlssNightmare EndlssNightmare
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
black-shadow-007 Credited to black-shadow-007
WsgiDAV MySQL provider has a blind SQL injection High
CVE-2026-55509 was published for WsgiDAV (pip) Aug 28, 2026
Jvr2022 Credited to Jvr2022
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
eml_parser vulnerable to DoS via deeply nested parens in Received headers High
CVE-2026-55620 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` High
CVE-2026-55585 was published for qwed (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion High
GHSA-8cp3-qxj6-px34 was published for utcp-http (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target High
GHSA-9qhg-99ww-9mqc was published for utcp-http (pip) Aug 25, 2026
lexdotdev Credited to lexdotdev
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced High
CVE-2026-55541 was published for PraisonAI (pip) Aug 25, 2026
saisathvik1 Credited to saisathvik1
evertrustai Credited to evertrustai
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks High
CVE-2026-55540 was published for PraisonAI (pip) Aug 25, 2026
riodrwn Credited to riodrwn
ProTip! Advisories are also available from the GraphQL API