Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,917 advisories

Loading
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
Flawfinder output manipulation via untrusted filenames and source text High
CVE-2026-48813 was published for flawfinder (pip) Jun 26, 2026
OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere High
CVE-2026-43003 was published for ironic-python-agent (pip) May 1, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
pypdf: Possible large memory usage for large /ToUnicode streams Moderate
CVE-2026-71870 was published for pypdf (pip) Aug 7, 2026
idisdi Credited to idisdi and stefan6419846 stefan6419846 stefan6419846
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API High
CVE-2026-48169 was published for praisonai-platform (pip) May 29, 2026
joshuaalwin Credited to joshuaalwin
Keras: HDF5 links can disclose local file contents Moderate
CVE-2026-9335 was published for keras (pip) Aug 2, 2026
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data High
CVE-2026-12484 was published for keras (pip) Jul 19, 2026
Keras: tar extraction permits symlink-based path traversal Low
CVE-2026-12482 was published for keras (pip) Jul 14, 2026
Keras: Lambda deserialization can bypass safe mode and execute code High
CVE-2026-12481 was published for keras (pip) Jul 3, 2026
Keras: HDF5 virtual datasets can disclose local files Moderate
CVE-2026-12480 was published for keras (pip) Jul 1, 2026
Keras: DiskIOStore permits path traversal through crafted layer names Moderate
CVE-2026-12479 was published for keras (pip) Jun 22, 2026
Keras archive extraction utilities allow path traversal and arbitrary file writes High
CVE-2026-11816 was published for keras (pip) Jun 11, 2026
hahwul Credited to hahwul
Django: signed cookies are vulnerable to salt namespace collisions Low
CVE-2026-6873 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
cgurnik Credited to cgurnik and hahwul hahwul hahwul
Django: GDALRaster may over-read heap memory when constructed from bytes Moderate
CVE-2026-53877 was published for django (pip) Jul 7, 2026
Django: DomainNameValidator permits newline characters that may enable HTTP header injection Moderate
CVE-2026-53878 was published for django (pip) Jul 7, 2026
Django: has_vary_header may expose cached responses when Vary values contain whitespace Low
CVE-2026-48587 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
cgurnik Credited to cgurnik
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token Critical
CVE-2026-48039 was published for meta-ads-mcp (pip) Jun 11, 2026
232-323 Credited to 232-323
OpenStack Neutron Improper Input Validation vulnerability Moderate
CVE-2015-3221 was published for neutron (pip) May 14, 2022
cardoe Credited to cardoe
pypdf: Possible long runtimes/large memory usage for large CID font width ranges Moderate
CVE-2026-71852 was published for pypdf (pip) Aug 7, 2026
7thParkk Credited to 7thParkk and stefan6419846 stefan6419846 stefan6419846
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
ProTip! Advisories are also available from the GraphQL API