Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,060 advisories

Loading
RestrictedPython guard hooks can be shadowed via positional-only arguments High
CVE-2026-55830 was published for RestrictedPython (pip) Aug 28, 2026
Neroli-realy Credited to Neroli-realy, dataflake, and taisehub dataflake dataflake
taisehub taisehub
AIIR verification and policy gates could report success without enforcing the control (fail-open) Moderate
GHSA-73p9-6hrp-8qhr was published for aiir (pip) Aug 28, 2026
plone.app.event vulnerable to denial of service via iCalendar import Critical
CVE-2026-55247 was published for plone.app.event (pip) Aug 28, 2026
H3xV0rT3x Credited to H3xV0rT3x, nijel, and EndlssNightmare nijel nijel
EndlssNightmare EndlssNightmare
YHalo-wyh Credited to YHalo-wyh and nijel nijel nijel
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet Critical
CVE-2026-55248 was published for plone.app.portlets (pip) Aug 28, 2026
black-shadow-007 Credited to black-shadow-007
WsgiDAV MySQL provider has a blind SQL injection High
CVE-2026-55509 was published for WsgiDAV (pip) Aug 28, 2026
Jvr2022 Credited to Jvr2022
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
aiosmtplib: STARTTLS response injection Moderate
CVE-2026-55558 was published for aiosmtplib (pip) Aug 27, 2026
WebOb: Open redirect in Location header normalization via leading C0 control / space characters Moderate
CVE-2026-54770 was published for webob (pip) Aug 27, 2026
tonghuaroot Credited to tonghuaroot, digitalresistor, and polkorny digitalresistor digitalresistor
polkorny polkorny
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
dizconnectz Credited to dizconnectz and nemesifier nemesifier nemesifier
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
muslimbek-0x Credited to muslimbek-0x
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login Moderate
CVE-2026-54338 was published for jupyterhub (pip) Aug 25, 2026
mauriceng98 Credited to mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk Zyy0530 Zyy0530
Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
eml_parser vulnerable to DoS via deeply nested parens in Received headers High
CVE-2026-55620 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
eml_parser has parser DoS via deeply nested parentheses in e-mail headers Moderate
CVE-2026-55619 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
ProTip! Advisories are also available from the GraphQL API