GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,081 advisories
Filter by severity
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Moderate
CVE-2026-84310
was published
for
pypdf
(pip)
Sep 1, 2026
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
Moderate
CVE-2026-84311
was published
for
pypdf
(pip)
Sep 1, 2026
pypdf: Possible infinite loop for TreeObject.insert_child
Moderate
CVE-2026-84309
was published
for
pypdf
(pip)
Sep 1, 2026
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
Moderate
CVE-2026-84305
was published
for
sqlparse
(pip)
Sep 1, 2026
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
CVE-2026-79675
was published
for
nltk
(pip)
Sep 1, 2026
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
Moderate
GHSA-8423-8fgw-73vq
was published
for
tornado
(pip)
Sep 1, 2026
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Low
GHSA-wwv5-g3v4-889x
was published
for
tornado
(pip)
Sep 1, 2026
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Moderate
CVE-2026-73228
was published
for
djangorestframework
(pip)
Sep 1, 2026
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Moderate
CVE-2026-73229
was published
for
djangorestframework
(pip)
Sep 1, 2026
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
High
GHSA-gqvg-gmmx-x4hm
was published
for
mlflow
(pip)
Sep 1, 2026
RestrictedPython guard hooks can be shadowed via positional-only arguments
High
CVE-2026-55830
was published
for
RestrictedPython
(pip)
Aug 28, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
plone.app.event vulnerable to denial of service via iCalendar import
Critical
CVE-2026-55247
was published
for
plone.app.event
(pip)
Aug 28, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
High
CVE-2026-55228
was published
for
Weblate
(pip)
Aug 28, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Moderate
CVE-2026-55227
was published
for
weblate
(pip)
Aug 28, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet
Critical
CVE-2026-55248
was published
for
plone.app.portlets
(pip)
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
WsgiDAV MySQL provider has a blind SQL injection
High
CVE-2026-55509
was published
for
WsgiDAV
(pip)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
aiosmtplib: STARTTLS response injection
Moderate
CVE-2026-55558
was published
for
aiosmtplib
(pip)
Aug 27, 2026
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
Moderate
CVE-2026-54770
was published
for
webob
(pip)
Aug 27, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API