Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
AIOHTTP vulnerable to denial of service through large payloads Moderate
CVE-2025-69228 was published for aiohttp (pip) Jan 5, 2026
ThomasRinsma Credited to ThomasRinsma, Finder16, and Dreamsorcerer Finder16 Finder16
Dreamsorcerer Dreamsorcerer
AIOHTTP vulnerable to DoS through chunked messages Moderate
CVE-2025-69229 was published for aiohttp (pip) Jan 5, 2026
Finder16 Credited to Finder16 and Dreamsorcerer Dreamsorcerer Dreamsorcerer
AIOHTTP Vulnerable to Cookie Parser Warning Storm Low
CVE-2025-69230 was published for aiohttp (pip) Jan 5, 2026
Finder16 Credited to Finder16 and Dreamsorcerer Dreamsorcerer Dreamsorcerer
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages Low
CVE-2026-26013 was published for langchain-core (pip) Feb 11, 2026
Finder16 Credited to Finder16
Envoy affected by off-by-one write in JsonEscaper::escapeString() Moderate
CVE-2026-26309 was published for github.com/envoyproxy/envoy (Go) Mar 10, 2026
Finder16 Credited to Finder16, agrawroh, phlax, and botengyao agrawroh agrawroh
phlax phlax botengyao botengyao
Tornado vulnerable to Header Injection and XSS via reason argument Moderate
CVE-2025-67724 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16 and Cheshire1225 Cheshire1225 Cheshire1225
Tornado: Quadratic DoS via Repeated Header Coalescing High
CVE-2025-67725 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16
Tornado: Quadratic DoS via Crafted Multipart Parameters High
CVE-2025-67726 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16
ProTip! Advisories are also available from the GraphQL API