Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

741 advisories

Loading
LiteLLM: Authentication Bypass via Host Header Injection Critical
CVE-2026-49468 was published for litellm (pip) Jun 16, 2026
LilThawg29 Credited to LilThawg29
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP Critical
CVE-2026-44727 was published for jupyter-server (pip) Jun 18, 2026
pikaball Credited to pikaball, y011d4, 0xHunSec, Yann-P, and Carreau y011d4 y011d4
0xHunSec 0xHunSec Yann-P Yann-P Carreau Carreau
vLLM: OpenAI auth bypass Critical
CVE-2026-48746 was published for vllm (pip) Jun 16, 2026
x41j Credited to x41j, russellb, and DarkLight1337 russellb russellb
DarkLight1337 DarkLight1337
vLLM has RCE In Video Processing Critical
CVE-2026-22778 was published for vllm (pip) Feb 2, 2026
dan-sec-ops Credited to dan-sec-ops, DarkLight1337, and russellb DarkLight1337 DarkLight1337
russellb russellb
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service Critical
CVE-2025-47277 was published for vllm (pip) May 20, 2025
kikayli Credited to kikayli, russellb, and funscoietyxboyz russellb russellb
funscoietyxboyz funscoietyxboyz
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed Critical
CVE-2026-41283 was published for mistral (pip) Jun 4, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval Critical
CVE-2026-61667 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input Critical
CVE-2026-45579 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory Critical
CVE-2026-50203 was published for apache-airflow-providers-sftp (pip) Jun 17, 2026
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine Critical
CVE-2026-42252 was published for apache-airflow (pip) Jun 1, 2026
UEFI Firmware Parser has a heap out-of-bounds write in tiano decompressor ReadCLen Critical
CVE-2026-54334 was published for uefi-firmware (pip) Apr 16, 2026
1seal Credited to 1seal
UEFI Firmware Parser has a stack out-of-bounds write in tiano decompressor MakeTable Critical
CVE-2026-54333 was published for uefi-firmware (pip) Apr 16, 2026
1seal Credited to 1seal
LoLLMs is vulnerable to Improper Access Control through weak secret key Critical
CVE-2026-1114 was published for lollms (pip) Apr 7, 2026
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView Critical
CVE-2026-42601 was published for archivebox (pip) May 4, 2026
q1uf3ng Credited to q1uf3ng
YLChen-007 Credited to YLChen-007
Duplicate Advisory: Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION) Critical
GHSA-hrvg-gx3j-wh53 was published for openbabel (pip) Jul 21, 2023 withdrawn
Numpy Deserialization of Untrusted Data Critical
CVE-2019-6446 was published for numpy (pip) May 24, 2022
cookesan Credited to cookesan
Kedro deserialization vulnerability Critical
CVE-2024-9701 was published for kedro (pip) Mar 20, 2025
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint Critical
CVE-2024-2952 was published for litellm (pip) Apr 10, 2024
ishaan-jaff Credited to ishaan-jaff, r3kumar, and cookesan r3kumar r3kumar
cookesan cookesan
langchain vulnerable to arbitrary code execution Critical
CVE-2023-36188 was published for langchain (pip) Jul 6, 2023
cookesan Credited to cookesan
asyncmy is vulnerable to SQL injection via crafted dict keys Critical
CVE-2025-65896 was published for asyncmy (pip) Dec 2, 2025
jfsoden Credited to jfsoden
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection Critical
CVE-2026-52830 was published for fast-mcp-telegram (pip) Jul 2, 2026
DavidCarliez Credited to DavidCarliez
ProTip! Advisories are also available from the GraphQL API