Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

646 advisories

Loading
claude-mem: The computeObservationContentHash Function is Vulnerable to Hash Collision Low
CVE-2026-11330 was published for claude-mem (npm) Jun 5, 2026
LMCache: 16-bit multimodal hash collision can poison KV cache entries Low
CVE-2026-10813 was published for lmcache (pip) Jun 4, 2026
MLflow: Deterministic sampling in dataset digest enables predictable collisions Low
CVE-2026-10803 was published for mlflow (pip) Jun 4, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission Low
CVE-2026-10804 was published for streamlit (pip) Jun 4, 2026
ms-swift: Image Cache Hash Collision via Missing Dimension Metadata Low
CVE-2026-10801 was published for ms-swift (pip) Jun 4, 2026
Gradio: Audio cache key ignores metadata when saving numpy audio outputs Low
CVE-2026-10783 was published for gradio (pip) Jun 4, 2026
HAXcms: Private Key Disclosure via Broken HMAC Implementation Critical
CVE-2026-46395 was published for @haxtheweb/haxcms-nodejs (npm) May 19, 2026
shreyas-challa Credited to shreyas-challa
Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens Moderate
CVE-2026-45701 was published for sulu/sulu (Composer) May 18, 2026
gangadhar-s-k Credited to gangadhar-s-k, mamazu, alexander-schranz, and Prokyonn mamazu mamazu
alexander-schranz alexander-schranz Prokyonn Prokyonn
Paramiko rsakey.py allows the SHA-1 algorithm Low
CVE-2026-44405 was published for paramiko (pip) May 6, 2026
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm Low
CVE-2026-7845 was published for langchain-chatchat (pip) May 5, 2026
Gitea has insecure default SSH settings Moderate
GHSA-3m6q-h5gj-7mrw was published for code.gitea.io/gitea (Go) Apr 22, 2026
gnzsnz Credited to gnzsnz
ProTip! Advisories are also available from the GraphQL API