GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,203 advisories
Filter by severity
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
High
CVE-2025-71358
was published
for
picklescan
(pip)
Aug 26, 2025
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
High
CVE-2026-54567
was published
for
Flask-Reuploaded
(pip)
Jul 17, 2026
Prompty: Arbitrary file read via file reference expansion
High
CVE-2026-53598
was published
for
@prompty/core
(npm)
Jul 17, 2026
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
High
CVE-2026-54547
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
High
CVE-2026-54549
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
sh _uid does not drop supplementary groups (incomplete privilege drop)
High
CVE-2026-54552
was published
for
sh
(pip)
Jul 17, 2026
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
High
CVE-2026-55574
was published
for
vllm
(pip)
Jul 17, 2026
vLLM has Remote DoS via Invalid Recovered Token Reinjection
High
CVE-2026-54234
was published
for
vllm
(pip)
Jul 17, 2026
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
High
GHSA-g5r6-gv6m-f5jv
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
High
CVE-2026-27893
was published
for
vllm
(pip)
Mar 27, 2026
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
High
CVE-2026-24779
was published
for
vllm
(pip)
Jan 28, 2026
vLLM affected by RCE via auto_map dynamic module loading during model initialization
High
CVE-2026-22807
was published
for
vllm
(pip)
Jan 21, 2026
vLLM vulnerable to remote code execution via transformers_utils/get_config
High
CVE-2025-66448
was published
for
vllm
(pip)
Dec 2, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
High
CVE-2025-62372
was published
for
vllm
(pip)
Nov 20, 2025
vLLM deserialization vulnerability leading to DoS and potential RCE
High
CVE-2025-62164
was published
for
vllm
(pip)
Nov 20, 2025
vLLM is vulnerable to timing attack at bearer auth
High
CVE-2025-59425
was published
for
vllm
(pip)
Oct 7, 2025
vllm API endpoints vulnerable to Denial of Service Attacks
High
CVE-2025-48956
was published
for
vllm
(pip)
Aug 21, 2025
Data exposure via ZeroMQ on multi-node vLLM deployment
High
CVE-2025-30202
was published
for
vllm
(pip)
Apr 29, 2025
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
High
CVE-2025-30165
was published
for
vllm
(pip)
May 6, 2025
Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
High
CVE-2026-54293
was published
for
nltk
(pip)
Jun 16, 2026
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
High
CVE-2026-59950
was published
for
mcp
(pip)
Jul 16, 2026
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
High
CVE-2026-52869
was published
for
mcp
(pip)
Jul 16, 2026
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
High
CVE-2026-52870
was published
for
mcp
(pip)
Jul 16, 2026
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution
High
CVE-2026-11332
was published
for
ansible-core
(pip)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API