GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,081 advisories
Filter by severity
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Moderate
CVE-2026-84310
was published
for
pypdf
(pip)
Sep 1, 2026
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
Moderate
CVE-2026-84311
was published
for
pypdf
(pip)
Sep 1, 2026
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
Moderate
CVE-2026-84305
was published
for
sqlparse
(pip)
Sep 1, 2026
pypdf: Possible infinite loop for TreeObject.insert_child
Moderate
CVE-2026-84309
was published
for
pypdf
(pip)
Sep 1, 2026
eth-abi is vulnerable to recursive DoS
Moderate
GHSA-3qwc-47jf-5rf7
was published
for
eth-abi
(pip)
Mar 5, 2024
Apache Airflow Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-45360
was published
for
apache-airflow
(pip)
Jun 1, 2026
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
CVE-2026-79675
was published
for
nltk
(pip)
Sep 1, 2026
Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
GHSA-3h2g-j4wp-7qqq
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
Moderate
GHSA-pv39-qrfq-g8gc
was published
for
nltk
(pip)
Aug 3, 2026
•
withdrawn
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)
High
GHSA-54xp-3ww7-6wjg
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Moderate
CVE-2026-12570
was published
for
keras
(pip)
Aug 10, 2026
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
Moderate
GHSA-8423-8fgw-73vq
was published
for
tornado
(pip)
Sep 1, 2026
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Low
GHSA-wwv5-g3v4-889x
was published
for
tornado
(pip)
Sep 1, 2026
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Moderate
CVE-2026-73228
was published
for
djangorestframework
(pip)
Sep 1, 2026
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Moderate
CVE-2026-73229
was published
for
djangorestframework
(pip)
Sep 1, 2026
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
High
CVE-2026-9856
was published
for
transformers
(pip)
Aug 2, 2026
pip would incorrectly handle doubly-encoded package URLs from indexes
Moderate
CVE-2026-13346
was published
for
pip
(pip)
Jul 29, 2026
kafka-python vulnerable to denial of service through an unbounded SCRAM iteration count
High
CVE-2026-10143
was published
for
kafka-python
(pip)
Jun 11, 2026
kafka-python vulnerable to denial of service through an unvalidated protocol frame length
High
CVE-2026-10142
was published
for
kafka-python
(pip)
Jun 11, 2026
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
High
GHSA-gqvg-gmmx-x4hm
was published
for
mlflow
(pip)
Sep 1, 2026
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
High
CVE-2026-41608
was published
for
thrift
(pip)
Jul 27, 2026
cbor2 C extension decoder flaws can cause denial of service
High
CVE-2025-64076
was published
for
cbor2
(pip)
Nov 18, 2025
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API