GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,026
Maven
5,000+
npm
4,763
NuGet
824
pip
4,366
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
35 advisories
Filter by severity
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
High
CVE-2026-26007
was published
for
cryptography
(pip)
Feb 10, 2026
Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1945
was published
for
picklescan
(pip)
Mar 10, 2025
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
AsyncSSH Rogue Extension Negotiation
Moderate
CVE-2023-46445
was published
for
asyncssh
(pip)
Nov 9, 2023
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
High
CVE-2025-59420
was published
for
authlib
(pip)
Sep 22, 2025
Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Moderate
GHSA-vv6j-3g6g-2pvj
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Moderate
GHSA-vr7h-p6mm-wpmh
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
Moderate
GHSA-f745-w6jp-hpxx
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression
Moderate
GHSA-f4x7-rfwp-v3xw
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get
Moderate
GHSA-86cj-95qr-2p4f
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
Moderate
GHSA-4r9r-ch6f-vxmx
was published
for
picklescan
(pip)
Aug 22, 2025
Gradio CORS Origin Validation Bypass Vulnerability
Low
CVE-2025-5320
was published
for
gradio
(pip)
May 29, 2025
Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-2fh4-gpch-vqv4
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-w6mr-mj53-x258
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Certifi removes GLOBALTRUST root certificate
Low
CVE-2024-39689
was published
for
certifi
(pip)
Jul 5, 2024
Removal of e-Tugra root certificate
High
CVE-2023-37920
was published
for
certifi
(pip)
Jul 25, 2023
Certifi removing TrustCor root certificate
Moderate
CVE-2022-23491
was published
for
certifi
(pip)
Dec 7, 2022
aiosmtpd vulnerable to SMTP smuggling
Moderate
CVE-2024-27305
was published
for
aiosmtpd
(pip)
Mar 13, 2024
Gradio lacks integrity checking on the downloaded FRP client
High
CVE-2024-47867
was published
for
gradio
(pip)
Oct 10, 2024
OpenStack Neutron can use an incorrect ID during policy enforcement
Moderate
CVE-2024-53916
was published
for
neutron
(pip)
Nov 25, 2024
vantage6-server node accepts non-whitelisted algorithms from malicious server
High
CVE-2023-47631
was published
for
vantage6-node
(pip)
Nov 14, 2023
Invalid root may become trusted root in The Update Framework (TUF)
Moderate
CVE-2020-15163
was published
for
tuf
(pip)
Sep 9, 2020
ProTip!
Advisories are also available from the
GraphQL API