GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
20 advisories
Filter by severity
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Moderate
CVE-2026-92952
was published
for
vm2
(npm)
Oct 1, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
Moderate
GHSA-56m6-8q75-f2rw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
Moderate
CVE-2026-55597
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
CVE-2026-73416
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
PraisonAI: SpiderTools redirect-target SSRF protection bypass
Moderate
CVE-2026-57115
was published
for
praisonaiagents
(pip)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API