GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
534 advisories
Filter by severity
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Low
GHSA-wwv5-g3v4-889x
was published
for
tornado
(pip)
Sep 1, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
Wagtail: Identification of documents by SHA1 hash
Low
GHSA-92hv-j533-69wc
was published
for
wagtail
(pip)
Aug 20, 2026
MobSF has SSRF port restriction bypass in assetlinks_check
Low
CVE-2026-68927
was published
for
mobsf
(pip)
Aug 18, 2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Low
CVE-2026-70483
was published
for
open-webui
(pip)
Aug 4, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Low
CVE-2026-59213
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Low
CVE-2026-59715
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
Low
CVE-2026-63632
was published
for
onnx
(pip)
Jul 24, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
Low
CVE-2026-59821
was published
for
litellm
(pip)
Jul 22, 2026
LiteLLM: Local file read via request-supplied OIDC file references
Low
CVE-2026-59819
was published
for
litellm
(pip)
Jul 22, 2026
Wasmtime: Memory leak in C API with `externref` and `anyref` types
Low
CVE-2025-61670
was published
for
wasmtime-bin
(pip)
Jul 14, 2026
Keras: tar extraction permits symlink-based path traversal
Low
CVE-2026-12482
was published
for
keras
(pip)
Jul 14, 2026
Django: cache middleware may expose private responses when unrelated request cookies are present
Low
CVE-2026-48588
was published
for
django
(pip)
Jul 7, 2026
Kiwi TCMS vulnerable to stored XSS via JavaScript: URI in extra_link field (TestPlan & TestCase)
Low
CVE-2026-55630
was published
for
kiwitcms
(pip)
Jul 6, 2026
Linuxfabrik Monitoring Plugins allow insecure creation of SQLite databases
Low
CVE-2026-53759
was published
for
linuxfabrik-lib
(pip)
Jul 6, 2026
Kiwi TCMS's /init-db/ page renders and responds to requests after first use
Low
CVE-2026-49292
was published
for
kiwitcms
(pip)
Jul 2, 2026
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
Low
CVE-2025-10998
was published
for
openbabel
(pip)
Jul 1, 2026
Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
Low
CVE-2025-10995
was published
for
openbabel
(pip)
Jun 30, 2026
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
Low
CVE-2025-10994
was published
for
openbabel
(pip)
Jun 30, 2026
Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
Low
CVE-2026-3408
was published
for
openbabel
(pip)
Jun 30, 2026
ProTip!
Advisories are also available from the
GraphQL API