GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
741 advisories
Filter by severity
LiteLLM: Authentication Bypass via Host Header Injection
Critical
CVE-2026-49468
was published
for
litellm
(pip)
Jun 16, 2026
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Critical
CVE-2026-44727
was published
for
jupyter-server
(pip)
Jun 18, 2026
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
Critical
CVE-2025-47277
was published
for
vllm
(pip)
May 20, 2025
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
Critical
CVE-2026-41283
was published
for
mistral
(pip)
Jun 4, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Critical
CVE-2026-61667
was published
for
DIRAC
(pip)
Jul 13, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Critical
CVE-2026-45579
was published
for
DIRAC
(pip)
Jul 13, 2026
MLflow: Environment variable injection in AI Gateway secrets enables server-side credential exfiltration
Critical
CVE-2026-4035
was published
for
mlflow
(pip)
Jun 3, 2026
Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
Critical
CVE-2026-50203
was published
for
apache-airflow-providers-sftp
(pip)
Jun 17, 2026
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Critical
CVE-2026-42252
was published
for
apache-airflow
(pip)
Jun 1, 2026
UEFI Firmware Parser has a heap out-of-bounds write in tiano decompressor ReadCLen
Critical
CVE-2026-54334
was published
for
uefi-firmware
(pip)
Apr 16, 2026
UEFI Firmware Parser has a stack out-of-bounds write in tiano decompressor MakeTable
Critical
CVE-2026-54333
was published
for
uefi-firmware
(pip)
Apr 16, 2026
LoLLMs is vulnerable to Improper Access Control through weak secret key
Critical
CVE-2026-1114
was published
for
lollms
(pip)
Apr 7, 2026
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
Critical
CVE-2026-42601
was published
for
archivebox
(pip)
May 4, 2026
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Critical
CVE-2026-55615
was published
for
langroid
(pip)
Jul 6, 2026
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Critical
CVE-2026-54769
was published
for
langroid
(pip)
Jul 6, 2026
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Critical
CVE-2026-54760
was published
for
langroid
(pip)
Jul 6, 2026
Duplicate Advisory: Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
Critical
GHSA-hrvg-gx3j-wh53
was published
for
openbabel
(pip)
Jul 21, 2023
•
withdrawn
Numpy Deserialization of Untrusted Data
Critical
CVE-2019-6446
was published
for
numpy
(pip)
May 24, 2022
Kedro deserialization vulnerability
Critical
CVE-2024-9701
was published
for
kedro
(pip)
Mar 20, 2025
LiteLLM has Server-Side Template Injection vulnerability in /completions endpoint
Critical
CVE-2024-2952
was published
for
litellm
(pip)
Apr 10, 2024
langchain vulnerable to arbitrary code execution
Critical
CVE-2023-36188
was published
for
langchain
(pip)
Jul 6, 2023
asyncmy is vulnerable to SQL injection via crafted dict keys
Critical
CVE-2025-65896
was published
for
asyncmy
(pip)
Dec 2, 2025
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
Critical
CVE-2026-52830
was published
for
fast-mcp-telegram
(pip)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API