Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,081 advisories

Loading
pypdf: Possible long runtimes/large memory usage when retrieving outlines Moderate
CVE-2026-84310 was published for pypdf (pip) Sep 1, 2026
stefan6419846 Credited to stefan6419846 and HYUNSUNG03 HYUNSUNG03 HYUNSUNG03
pypdf: Possible long runtimes/large memory usage when extracting XForm objects Moderate
CVE-2026-84311 was published for pypdf (pip) Sep 1, 2026
zikk090 Credited to zikk090 and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible infinite loop for TreeObject.insert_child Moderate
CVE-2026-84309 was published for pypdf (pip) Sep 1, 2026
alienkeric Credited to alienkeric and stefan6419846 stefan6419846 stefan6419846
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
arpitjain099 Credited to arpitjain099
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests Moderate
CVE-2026-73229 was published for djangorestframework (pip) Sep 1, 2026
zainnadeem786 Credited to zainnadeem786
prasanna8585 Credited to prasanna8585
RestrictedPython guard hooks can be shadowed via positional-only arguments High
CVE-2026-55830 was published for RestrictedPython (pip) Aug 28, 2026
Neroli-realy Credited to Neroli-realy, dataflake, and taisehub dataflake dataflake
taisehub taisehub
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
plone.app.event vulnerable to denial of service via iCalendar import Critical
CVE-2026-55247 was published for plone.app.event (pip) Aug 28, 2026
H3xV0rT3x Credited to H3xV0rT3x, nijel, and EndlssNightmare nijel nijel
EndlssNightmare EndlssNightmare
YHalo-wyh Credited to YHalo-wyh and nijel nijel nijel
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet Critical
CVE-2026-55248 was published for plone.app.portlets (pip) Aug 28, 2026
black-shadow-007 Credited to black-shadow-007
WsgiDAV MySQL provider has a blind SQL injection High
CVE-2026-55509 was published for WsgiDAV (pip) Aug 28, 2026
Jvr2022 Credited to Jvr2022
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
aiosmtplib: STARTTLS response injection Moderate
CVE-2026-55558 was published for aiosmtplib (pip) Aug 27, 2026
WebOb: Open redirect in Location header normalization via leading C0 control / space characters Moderate
CVE-2026-54770 was published for webob (pip) Aug 27, 2026
tonghuaroot Credited to tonghuaroot, digitalresistor, and polkorny digitalresistor digitalresistor
polkorny polkorny
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
ProTip! Advisories are also available from the GraphQL API