GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,169
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
Critical
GHSA-j6c9-qvp8-699f
was published
for
picklescan
(pip)
Jun 17, 2026
•
withdrawn
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
Critical
GHSA-rmpp-8wf5-xx5q
was published
for
picklescan
(pip)
Jun 17, 2026
•
withdrawn
APScheduler's JSONSerializer and CBORSerializer are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2026-31072
was published
for
apscheduler
(pip)
May 19, 2026
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
Critical
CVE-2026-7301
was published
for
sglang
(pip)
May 18, 2026
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
Critical
CVE-2026-7304
was published
for
sglang
(pip)
May 18, 2026
imgaug contains an insecure deserialization vulnerability in BackgroundAugmenter class within multicore.py module
Critical
CVE-2026-31235
was published
for
imgaug
(pip)
May 12, 2026
Ludwig framework is vulnerable to insecure deserialization through its predict() method.
Critical
CVE-2026-31237
was published
for
ludwig
(pip)
May 12, 2026
Ludwig framework is vulnerable to insecure deserialization in its model serving component
Critical
CVE-2026-31238
was published
for
ludwig
(pip)
May 12, 2026
mamba language model framework vulnerable to insecure deserialization when loading pre-trained models from HuggingFace Hub
Critical
CVE-2026-31239
was published
for
mamba-ssm
(pip)
May 12, 2026
Horovod contains an insecure deserialization vulnerability in its KVStore HTTP server component
Critical
CVE-2026-31234
was published
for
horovod
(pip)
May 12, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Critical
CVE-2025-62373
was published
for
pipecat-ai
(pip)
Apr 23, 2026
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
Critical
CVE-2026-39890
was published
for
praisonai
(pip)
Apr 8, 2026
Kedro has Arbitrary Code Execution via Malicious Logging Configuration
Critical
CVE-2026-35171
was published
for
kedro
(pip)
Apr 3, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
Critical
CVE-2026-3060
was published
for
sglang
(pip)
Mar 12, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
Critical
CVE-2026-3059
was published
for
sglang
(pip)
Mar 12, 2026
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Critical
CVE-2026-21531
was published
for
azure-ai-language-conversations-authoring
(pip)
Feb 10, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
Critical
CVE-2026-25632
was published
for
epyt-flow
(pip)
Feb 4, 2026
Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
Critical
CVE-2025-14931
was published
for
smolagents
(pip)
Dec 23, 2025
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Critical
CVE-2025-68664
was published
for
langchain-core
(pip)
Dec 23, 2025
Modular Max Serve has Unsafe Deserialization vulnerability
Critical
CVE-2025-60455
was published
for
modular
(pip)
Nov 18, 2025
Keras framework vulnerable to deserialization of untrusted data
Critical
CVE-2025-49655
was published
for
keras
(pip)
Oct 17, 2025
pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer
Critical
CVE-2025-62515
was published
for
pyquokka
(pip)
Oct 17, 2025
scio is vunerable to Remote Command Execution through PyTorch
Critical
GHSA-m9mp-6x32-5rhg
was published
for
scio-pypi
(pip)
Oct 9, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
apache-iotdb
(Maven)
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API