GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,060 advisories
Filter by severity
RestrictedPython guard hooks can be shadowed via positional-only arguments
High
CVE-2026-55830
was published
for
RestrictedPython
(pip)
Aug 28, 2026
AIIR verification and policy gates could report success without enforcing the control (fail-open)
Moderate
GHSA-73p9-6hrp-8qhr
was published
for
aiir
(pip)
Aug 28, 2026
plone.app.event vulnerable to denial of service via iCalendar import
Critical
CVE-2026-55247
was published
for
plone.app.event
(pip)
Aug 28, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
High
CVE-2026-55228
was published
for
Weblate
(pip)
Aug 28, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Moderate
CVE-2026-55227
was published
for
weblate
(pip)
Aug 28, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet
Critical
CVE-2026-55248
was published
for
plone.app.portlets
(pip)
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
WsgiDAV MySQL provider has a blind SQL injection
High
CVE-2026-55509
was published
for
WsgiDAV
(pip)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
aiosmtplib: STARTTLS response injection
Moderate
CVE-2026-55558
was published
for
aiosmtplib
(pip)
Aug 27, 2026
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
Moderate
CVE-2026-54770
was published
for
webob
(pip)
Aug 27, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
Moderate
GHSA-x287-5c68-36wp
was published
for
openwisp-ipam
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
kas Persistently Disables SSH Host Key Checking
Low
CVE-2026-54548
was published
for
kas
(pip)
Aug 26, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Moderate
CVE-2026-54553
was published
for
starlette-admin
(pip)
Aug 26, 2026
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
Moderate
CVE-2026-54338
was published
for
jupyterhub
(pip)
Aug 25, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Critical
CVE-2026-45018
was published
for
chainlit
(pip)
Aug 25, 2026
eml_parser vulnerable to DoS via deeply nested parens in Received headers
High
CVE-2026-55620
was published
for
eml_parser
(pip)
Aug 25, 2026
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
Moderate
CVE-2026-55619
was published
for
eml_parser
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API