GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,039
Maven
5,000+
npm
4,779
NuGet
824
pip
4,380
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
NVIDIA NeMo Framework Deserializes Untrusted Data
High
CVE-2025-33253
was published
for
nemo-toolkit
(pip)
Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution
High
CVE-2025-33245
was published
for
nemo-toolkit
(pip)
Feb 18, 2026
Duplicate Advisory: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-8x2r-v9x5-3qgh
was published
for
pdfminer.six
(pip)
Feb 3, 2026
•
withdrawn
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
High
CVE-2025-70560
was published
for
boltz
(pip)
Feb 3, 2026
picklescan missing detection by simple obfuscation of a `builtins.eval` call
High
GHSA-9m3x-qqw2-h32h
was published
for
picklescan
(pip)
Feb 2, 2026
PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
High
CVE-2026-24747
was published
for
pytorch
(pip)
Jan 27, 2026
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
High
CVE-2026-24009
was published
for
docling-core
(pip)
Jan 22, 2026
Azure Core is vulnerable to deserialization of untrusted data
High
CVE-2026-21226
was published
for
azure-core
(pip)
Jan 13, 2026
Fickling vulnerable to detection bypass due to "builtins" blindness
High
CVE-2026-22612
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
High
CVE-2026-22609
was published
for
fickling
(pip)
Jan 9, 2026
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
High
CVE-2026-22608
was published
for
fickling
(pip)
Jan 9, 2026
Fickling Blocklist Bypass: cProfile.run()
High
CVE-2026-22607
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has a bypass via runpy.run_path() and runpy.run_module()
High
CVE-2026-22606
was published
for
fickling
(pip)
Jan 9, 2026
vLLM introduced enhanced protection for CVE-2025-62164
High
GHSA-mcmc-2m55-j8jj
was published
for
vllm
(pip)
Jan 8, 2026
Feast vulnerable to Deserialization of Untrusted Data
High
CVE-2025-11157
was published
for
feast
(pip)
Jan 1, 2026
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-rrxm-2pvv-m66x
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
High
GHSA-x843-g5mx-g377
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-r8g5-cgf2-4m4m
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling pty.spawn
High
GHSA-vqmv-47xg-9wpr
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan vulnerable to Arbitrary File Writing
High
GHSA-m273-6v24-x4m4
was published
for
picklescan
(pip)
Dec 29, 2025
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
High
CVE-2025-67729
was published
for
lmdeploy
(pip)
Dec 26, 2025
Fickling has Code Injection vulnerability via pty.spawn()
High
CVE-2025-67748
was published
for
fickling
(pip)
Dec 15, 2025
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
High
CVE-2025-67747
was published
for
fickling
(pip)
Dec 15, 2025
ProTip!
Advisories are also available from the
GraphQL API