GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,228
Maven
5,000+
npm
3,895
NuGet
701
pip
3,661
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
562 advisories
Filter by severity
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-32375
was published
for
bentoml
(pip)
Apr 9, 2025
Picklescan failed to detect to some unsafe global function in Numpy library
Moderate
GHSA-fj43-3qmq-673f
was published
for
picklescan
(pip)
Apr 7, 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-27520
was published
for
bentoml
(pip)
Apr 4, 2025
jooby-pac4j: deserialization of untrusted data
High
CVE-2025-31129
was published
for
io.jooby:jooby-pac4j
(Maven)
Apr 1, 2025
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
Critical
CVE-2025-30065
was published
for
org.apache.parquet:parquet-avro
(Maven)
Apr 1, 2025
yiisoft Yii2 Deserialization of Untrusted Data
Moderate
CVE-2025-2689
was published
for
yiisoft/yii2-dev
(Composer)
Mar 24, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
InvokeAI Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-12029
was published
for
InvokeAI
(pip)
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
CVE-2025-30160
was published
for
redlib
(Rust)
Mar 21, 2025
Kedro deserialization vulnerability
Critical
CVE-2024-9701
was published
for
kedro
(pip)
Mar 20, 2025
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
Critical
CVE-2024-9052
was published
for
vllm
(pip)
Mar 20, 2025
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
Critical
CVE-2024-9053
was published
for
vllm
(pip)
Mar 20, 2025
BentoML deserialization vulnerability
Critical
CVE-2024-9070
was published
for
bentoml
(pip)
Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical
CVE-2024-8502
was published
for
agentscope
(pip)
Mar 20, 2025
Withdrawn Advisory: PyTorch deserialization vulnerability
Critical
CVE-2024-7804
was published
for
torch
(pip)
Mar 20, 2025
•
withdrawn
vLLM Deserialization of Untrusted Data vulnerability
Critical
CVE-2024-11041
was published
for
vllm
(pip)
Mar 20, 2025
H2O Deserialization of Untrusted Data Vulnerability
Critical
CVE-2024-10553
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Low
CVE-2024-47552
was published
for
org.apache.seata:seata-config-core
(Maven)
Mar 20, 2025
vLLM Allows Remote Code Execution via Mooncake Integration
Critical
CVE-2025-29783
was published
for
vllm
(pip)
Mar 19, 2025
Qiskit allows arbitrary code execution decoding QPY format versions < 13
Critical
CVE-2025-2000
was published
for
qiskit
(pip)
Mar 14, 2025
Duplicate Advisory: Qiskit allows arbitrary code execution decoding QPY format versions < 13
Critical
GHSA-3pwp-2fqj-6g2p
was published
for
qiskit
(pip)
Mar 14, 2025
•
withdrawn
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-33cr-m232-xqch
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 11, 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Critical
CVE-2025-24813
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Mar 10, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-jg6f-48ff-5xrw
was published
for
github.com/cosmos/ibc-go
(Go)
Feb 28, 2025
ProTip!
Advisories are also available from the
GraphQL API