GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
1,649 advisories
Filter by severity
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
High
CVE-2026-26007
was published
for
cryptography
(pip)
Feb 10, 2026
Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration)
High
CVE-2026-1669
was published
for
keras
(pip)
Feb 12, 2026
Pillow affected by out-of-bounds write when loading PSD images
High
CVE-2026-25990
was published
for
pillow
(pip)
Feb 11, 2026
Emmett-Core: Unhandled CookieError Exception Causing Denial of Service
High
CVE-2026-25577
was published
for
emmett-core
(pip)
Feb 10, 2026
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
High
CVE-2025-53000
was published
for
nbconvert
(pip)
Dec 18, 2025
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
High
CVE-2026-25478
was published
for
litestar
(pip)
Feb 9, 2026
MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
High
CVE-2026-25650
was published
for
mcp-salesforce-connector
(pip)
Feb 6, 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
High
CVE-2026-25732
was published
for
nicegui
(pip)
Feb 5, 2026
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
High
CVE-2026-25640
was published
for
pydantic-ai
(pip)
Feb 6, 2026
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
High
CVE-2026-25580
was published
for
pydantic-ai
(pip)
Feb 6, 2026
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
High
CVE-2026-1707
was published
for
pgadmin4
(pip)
Feb 5, 2026
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
aiohttp is vulnerable to directory traversal
High
CVE-2024-23334
was published
for
aiohttp
(pip)
Jan 29, 2024
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
High
CVE-2025-70560
was published
for
boltz
(pip)
Feb 3, 2026
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
High
CVE-2024-37301
was published
for
document-merge-service
(pip)
Jun 11, 2024
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
CVE-2025-70559
was published
for
pdfminer.six
(pip)
Nov 7, 2025
Duplicate Advisory: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-8x2r-v9x5-3qgh
was published
for
pdfminer.six
(pip)
Feb 3, 2026
•
withdrawn
SageMaker Python SDK has Exposed HMAC
High
CVE-2026-1777
was published
for
sagemaker
(pip)
Feb 2, 2026
SageMaker Python SDK has Insecure TLS Configuration
High
CVE-2026-1778
was published
for
sagemaker
(pip)
Feb 2, 2026
Duplicate Advisory: Gradio Local File Inclusion vulnerability
High
GHSA-3f95-mxq2-2f63
was published
for
gradio
(pip)
Apr 10, 2024
•
withdrawn
Apache Airflow proxy credentials for various providers might leak in task logs
High
CVE-2025-68675
was published
for
apache-airflow
(pip)
Jan 16, 2026
Chainlit contain a server-side request forgery (SSRF) vulnerability
High
CVE-2026-22219
was published
for
chainlit
(pip)
Jan 20, 2026
Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
High
CVE-2026-0599
was published
for
text-generation
(pip)
Feb 2, 2026
ProTip!
Advisories are also available from the
GraphQL API