GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,844
Maven
5,000+
npm
4,470
NuGet
779
pip
4,231
Pub
12
RubyGems
974
Rust
1,093
Swift
48
Unreviewed advisories
All unreviewed
5,000+
678 advisories
Filter by severity
TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool
Moderate
CVE-2026-0859
was published
for
typo3/cms-core
(Composer)
Jan 13, 2026
Azure Core is vulnerable to deserialization of untrusted data
High
CVE-2026-21226
was published
for
azure-core
(pip)
Jan 13, 2026
UmbracoForms Vulnerable to Remote Code Execution via Untrusted WSDL Compilation in Dynamic SOAP Client Generation
Critical
CVE-2025-68924
was published
for
UmbracoForms
(NuGet)
Jan 13, 2026
Fickling vulnerable to detection bypass due to "builtins" blindness
High
CVE-2026-22612
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
High
CVE-2026-22609
was published
for
fickling
(pip)
Jan 9, 2026
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
High
CVE-2026-22608
was published
for
fickling
(pip)
Jan 9, 2026
Fickling Blocklist Bypass: cProfile.run()
High
CVE-2026-22607
was published
for
fickling
(pip)
Jan 9, 2026
Fickling has a bypass via runpy.run_path() and runpy.run_module()
High
CVE-2026-22606
was published
for
fickling
(pip)
Jan 9, 2026
vLLM introduced enhanced protection for CVE-2025-62164
High
GHSA-mcmc-2m55-j8jj
was published
for
vllm
(pip)
Jan 8, 2026
Bio-Formats performs unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing
Moderate
CVE-2026-22187
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
Feast vulnerable to Deserialization of Untrusted Data
High
CVE-2025-11157
was published
for
feast
(pip)
Jan 1, 2026
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Moderate
GHSA-6556-fwc2-fg2p
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-rrxm-2pvv-m66x
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
Moderate
GHSA-cffc-mxrf-mhh4
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
High
GHSA-x843-g5mx-g377
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-r8g5-cgf2-4m4m
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling pty.spawn
High
GHSA-vqmv-47xg-9wpr
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan vulnerable to Arbitrary File Writing
High
GHSA-m273-6v24-x4m4
was published
for
picklescan
(pip)
Dec 29, 2025
lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
High
CVE-2025-67729
was published
for
lmdeploy
(pip)
Dec 26, 2025
LangChain serialization injection vulnerability enables secret extraction
High
CVE-2025-68665
was published
for
@langchain/core
(npm)
Dec 23, 2025
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Critical
CVE-2025-68664
was published
for
langchain-core
(pip)
Dec 23, 2025
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
High
CVE-2025-66524
was published
for
org.apache.nifi:nifi-asana-processors
(Maven)
Dec 19, 2025
ProTip!
Advisories are also available from the
GraphQL API