Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,081 advisories

Loading
pypdf: Possible long runtimes/large memory usage when retrieving outlines Moderate
CVE-2026-84310 was published for pypdf (pip) Sep 1, 2026
stefan6419846 Credited to stefan6419846 and HYUNSUNG03 HYUNSUNG03 HYUNSUNG03
pypdf: Possible long runtimes/large memory usage when extracting XForm objects Moderate
CVE-2026-84311 was published for pypdf (pip) Sep 1, 2026
zikk090 Credited to zikk090 and stefan6419846 stefan6419846 stefan6419846
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
pypdf: Possible infinite loop for TreeObject.insert_child Moderate
CVE-2026-84309 was published for pypdf (pip) Sep 1, 2026
alienkeric Credited to alienkeric and stefan6419846 stefan6419846 stefan6419846
eth-abi is vulnerable to recursive DoS Moderate
GHSA-3qwc-47jf-5rf7 was published for eth-abi (pip) Mar 5, 2024
paulmillr Credited to paulmillr and yhay81 yhay81 yhay81
Apache Airflow Vulnerable to Deserialization of Untrusted Data High
CVE-2026-45360 was published for apache-airflow (pip) Jun 1, 2026
dervoeti Credited to dervoeti
arpitjain099 Credited to arpitjain099
Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection Moderate
GHSA-pv39-qrfq-g8gc was published for nltk (pip) Aug 3, 2026 withdrawn
navaneethibm Credited to navaneethibm
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427) High
GHSA-54xp-3ww7-6wjg was published for nltk (pip) Aug 25, 2026 withdrawn
Keras model loading is vulnerable to denial of service through HDF5 shape bombs Moderate
CVE-2026-12570 was published for keras (pip) Aug 10, 2026
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests Moderate
CVE-2026-73229 was published for djangorestframework (pip) Sep 1, 2026
zainnadeem786 Credited to zainnadeem786
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names High
CVE-2026-9856 was published for transformers (pip) Aug 2, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes Moderate
CVE-2026-13346 was published for pip (pip) Jul 29, 2026
kafka-python vulnerable to denial of service through an unbounded SCRAM iteration count High
CVE-2026-10143 was published for kafka-python (pip) Jun 11, 2026
hahwul Credited to hahwul
kafka-python vulnerable to denial of service through an unvalidated protocol frame length High
CVE-2026-10142 was published for kafka-python (pip) Jun 11, 2026
hahwul Credited to hahwul
prasanna8585 Credited to prasanna8585
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
cbor2 C extension decoder flaws can cause denial of service High
CVE-2025-64076 was published for cbor2 (pip) Nov 18, 2025
vLLM: OpenAI auth bypass Critical
CVE-2026-48746 was published for vllm (pip) Jun 16, 2026
x41j Credited to x41j, russellb, and DarkLight1337 russellb russellb
DarkLight1337 DarkLight1337
pierreolivierbonin Credited to pierreolivierbonin and jperezdealgaba jperezdealgaba jperezdealgaba
ProTip! Advisories are also available from the GraphQL API