GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
259 advisories
Filter by severity
GitPython vulnerable to Remote Code Execution due to improper user input validation
Critical
CVE-2022-24439
was published
for
GitPython
(pip)
Dec 6, 2022
aiohttp's ClientSession is vulnerable to CRLF injection via version
Moderate
CVE-2023-49081
was published
for
aiohttp
(pip)
Nov 27, 2023
aiohttp's ClientSession is vulnerable to CRLF injection via method
Moderate
CVE-2023-49082
was published
for
aiohttp
(pip)
Nov 27, 2023
Duplicate Advisory: motionEye vulnerable to RCE via unsanitized motion config parameter
High
GHSA-26f6-wm47-7h7j
was published
for
motioneye
(pip)
Oct 3, 2025
•
withdrawn
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Moderate
CVE-2025-10164
was published
for
sglang
(pip)
Sep 9, 2025
Synapse vulnerable to federation denial of service via malformed events
High
CVE-2025-30355
was published
for
matrix-synapse
(pip)
Mar 27, 2025
SaltStack Salt is vulnerable Arbitrary Directory Access
High
CVE-2020-11652
was published
for
salt
(pip)
May 24, 2022
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Moderate
CVE-2025-61620
was published
for
vllm
(pip)
Oct 7, 2025
Kedro allows Remote Code Execution by Pulling Micro Packages
High
CVE-2024-12215
was published
for
kedro
(pip)
Mar 20, 2025
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical
CVE-2024-11042
was published
for
InvokeAI
(pip)
Mar 20, 2025
qdrant input validation failure
Critical
CVE-2024-3829
was published
for
qdrant-client
(pip)
Jun 3, 2024
Django Filer Unrestricted Upload of File with Dangerous Type
Moderate
CVE-2024-11404
was published
for
django-filer
(pip)
Nov 20, 2024
FastAPI Guard has a regex bypass
High
CVE-2025-54365
was published
for
fastapi-guard
(pip)
Jul 23, 2025
mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders
Moderate
CVE-2025-59940
was published
for
mkdocs-include-markdown-plugin
(pip)
Sep 29, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
Llama Stack could potentially allow for remote code execution
Moderate
CVE-2025-55178
was published
for
llama-stack
(pip)
Sep 24, 2025
Picklescan Bypass is Possible via File Extension Mismatch
Critical
CVE-2025-10155
was published
for
picklescan
(pip)
Sep 10, 2025
Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch
Critical
GHSA-j424-mc44-f4hj
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Pillow Denial of Service by Uncontrolled Resource Consumption
High
CVE-2021-27923
was published
for
pillow
(pip)
Mar 18, 2021
Pillow Denial of Service by Uncontrolled Resource Consumption
High
CVE-2021-27921
was published
for
Pillow
(pip)
Mar 18, 2021
Pillow Uncontrolled Resource Consumption
High
CVE-2021-27922
was published
for
pillow
(pip)
Mar 18, 2021
uv allows ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-54368
was published
for
uv
(pip)
Aug 7, 2025
ProTip!
Advisories are also available from the
GraphQL API