Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,203 advisories

Loading
FredericDT Credited to FredericDT
hackkim Credited to hackkim
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token High
CVE-2026-54547 was published for meta-ads-mcp (pip) Jul 17, 2026
EQSTLab Credited to EQSTLab
EQSTLab Credited to EQSTLab and useworld useworld useworld
sh _uid does not drop supplementary groups (incomplete privilege drop) High
CVE-2026-54552 was published for sh (pip) Jul 17, 2026
Gares95 Credited to Gares95
brodmart Credited to brodmart and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM has Remote DoS via Invalid Recovered Token Reinjection High
CVE-2026-54234 was published for vllm (pip) Jul 17, 2026
NeilAlfred Credited to NeilAlfred and jperezdealgaba jperezdealgaba jperezdealgaba
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment High
GHSA-g5r6-gv6m-f5jv was published for mcp-atlassian (pip) Jul 10, 2026
rainfantry Credited to rainfantry and Samielakkad Samielakkad Samielakkad
pierreolivierbonin Credited to pierreolivierbonin and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out High
CVE-2026-27893 was published for vllm (pip) Mar 27, 2026
Wernerina Credited to Wernerina and russellb russellb russellb
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector High
CVE-2026-24779 was published for vllm (pip) Jan 28, 2026
leishilong Credited to leishilong, leung-yao, Isotr0py, and russellb leung-yao leung-yao
Isotr0py Isotr0py russellb russellb
vLLM affected by RCE via auto_map dynamic module loading during model initialization High
CVE-2026-22807 was published for vllm (pip) Jan 21, 2026
zaddy6 Credited to zaddy6, arthurgervais, DarkLight1337, and russellb arthurgervais arthurgervais
DarkLight1337 DarkLight1337 russellb russellb
vLLM vulnerable to remote code execution via transformers_utils/get_config High
CVE-2025-66448 was published for vllm (pip) Dec 2, 2025
Vancir Credited to Vancir, Isotr0py, DarkLight1337, and russellb Isotr0py Isotr0py
DarkLight1337 DarkLight1337 russellb russellb
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs High
CVE-2025-62372 was published for vllm (pip) Nov 20, 2025
DarkLight1337 Credited to DarkLight1337, ywang96, Isotr0py, and russellb ywang96 ywang96
Isotr0py Isotr0py russellb russellb
vLLM deserialization vulnerability leading to DoS and potential RCE High
CVE-2025-62164 was published for vllm (pip) Nov 20, 2025
omriaxion Credited to omriaxion, russellb, DarkLight1337, Isotr0py, ywang96, and davidatom russellb russellb
DarkLight1337 DarkLight1337 Isotr0py Isotr0py ywang96 ywang96 davidatom davidatom
vLLM is vulnerable to timing attack at bearer auth High
CVE-2025-59425 was published for vllm (pip) Oct 7, 2025
NiuBlibing Credited to NiuBlibing and russellb russellb russellb
vllm API endpoints vulnerable to Denial of Service Attacks High
CVE-2025-48956 was published for vllm (pip) Aug 21, 2025
jperezdealgaba Credited to jperezdealgaba, russellb, and taneem-ibrahim russellb russellb
taneem-ibrahim taneem-ibrahim
Data exposure via ZeroMQ on multi-node vLLM deployment High
CVE-2025-30202 was published for vllm (pip) Apr 29, 2025
russellb Credited to russellb and kexinoh kexinoh kexinoh
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration High
CVE-2025-30165 was published for vllm (pip) May 6, 2025
avioligo Credited to avioligo and russellb russellb russellb
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
MCP Python SDK: WebSocket server transport does not support Host/Origin validation High
CVE-2026-59950 was published for mcp (pip) Jul 16, 2026
nitish-yaddala Credited to nitish-yaddala, Nadav0077, dodge1218, gistrec, and u-ktdi Nadav0077 Nadav0077
dodge1218 dodge1218 gistrec gistrec u-ktdi u-ktdi
srikanthramu Credited to srikanthramu and hewei-gikaku hewei-gikaku hewei-gikaku
cjmielke Credited to cjmielke, dewankpant, and shrutilohani dewankpant dewankpant
shrutilohani shrutilohani
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution High
CVE-2026-11332 was published for ansible-core (pip) Jun 5, 2026
ProTip! Advisories are also available from the GraphQL API