Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

510 advisories

Loading
PyTorch is vulnerable to memory corruption through its torch.jit.script function Low
CVE-2025-3000 was published for torch (pip) Mar 31, 2025
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map Low
CVE-2026-11312 was published for infinistore (pip) Jun 5, 2026
LMCache: 16-bit multimodal hash collision can poison KV cache entries Low
CVE-2026-10813 was published for lmcache (pip) Jun 4, 2026
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname Low
CVE-2026-54282 was published for Starlette (pip) Jun 15, 2026
nic-lovin Credited to nic-lovin
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters Low
CVE-2026-53537 was published for python-multipart (pip) Jun 15, 2026
0xkakash1 Credited to 0xkakash1 and sammiee5311 sammiee5311 sammiee5311
vmfunc Credited to vmfunc, oxqnd, and rodrigobnogueira oxqnd oxqnd
rodrigobnogueira rodrigobnogueira
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission Low
CVE-2026-10804 was published for streamlit (pip) Jun 4, 2026
MLflow: Deterministic sampling in dataset digest enables predictable collisions Low
CVE-2026-10803 was published for mlflow (pip) Jun 4, 2026
ms-swift: Image Cache Hash Collision via Missing Dimension Metadata Low
CVE-2026-10801 was published for ms-swift (pip) Jun 4, 2026
Gradio: Audio cache key ignores metadata when saving numpy audio outputs Low
CVE-2026-10783 was published for gradio (pip) Jun 4, 2026
Wasmtime: Memory leak in C API with `externref` and `anyref` types Low
CVE-2025-61670 was published for wasmtime-bin (pip) Jul 14, 2026
alexcrichton Credited to alexcrichton
Code Index MCP is vulnerable to Uncontrolled Resource Consumption Low
CVE-2026-10692 was published for code-index-mcp (pip) Jun 3, 2026
hermes-agent has an Injection issue Low
CVE-2026-10222 was published for hermes-agent (pip) Jun 1, 2026
Apache Airflow has an Incorrect Authorization issue Low
CVE-2026-45426 was published for apache-airflow (pip) Jun 1, 2026
Apache Airflow has an Improper Authorization issue Low
CVE-2026-40963 was published for apache-airflow (pip) Jun 1, 2026
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint Low
CVE-2026-10177 was published for aider-chat (pip) May 31, 2026
Aider is vulnerable to Code Injection via editor_coder.run function Low
CVE-2026-10175 was published for aider-chat (pip) May 31, 2026
ProTip! Advisories are also available from the GraphQL API