GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
510 advisories
Filter by severity
PyTorch is vulnerable to memory corruption through its torch.jit.script function
Low
CVE-2025-3000
was published
for
torch
(pip)
Mar 31, 2025
bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in InfiniStore KV Map
Low
CVE-2026-11312
was published
for
infinistore
(pip)
Jun 5, 2026
OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
Low
CVE-2026-50266
was published
for
neutron
(pip)
Jun 4, 2026
LMCache: 16-bit multimodal hash collision can poison KV cache entries
Low
CVE-2026-10813
was published
for
lmcache
(pip)
Jun 4, 2026
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Low
CVE-2026-54282
was published
for
Starlette
(pip)
Jun 15, 2026
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
Low
CVE-2026-53537
was published
for
python-multipart
(pip)
Jun 15, 2026
AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
Low
CVE-2026-34520
was published
for
aiohttp
(pip)
Apr 1, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
CVE-2026-10804
was published
for
streamlit
(pip)
Jun 4, 2026
GPTCache: File and image cache keys collide because BufferedReader.peek() only reads the buffered prefix
Low
CVE-2026-10812
was published
for
gptcache
(pip)
Jun 4, 2026
MLflow: Deterministic sampling in dataset digest enables predictable collisions
Low
CVE-2026-10803
was published
for
mlflow
(pip)
Jun 4, 2026
ms-swift: Image Cache Hash Collision via Missing Dimension Metadata
Low
CVE-2026-10801
was published
for
ms-swift
(pip)
Jun 4, 2026
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Low
CVE-2026-10783
was published
for
gradio
(pip)
Jun 4, 2026
mlrun: DataFrame hash collisions can cause dataset artifact path conflicts and silent data corruption
Low
CVE-2026-10766
was published
for
mlrun
(pip)
Jun 3, 2026
Wasmtime: Memory leak in C API with `externref` and `anyref` types
Low
CVE-2025-61670
was published
for
wasmtime-bin
(pip)
Jul 14, 2026
Django fails to prevent reuse of a partially-initialized connection after a failed `STARTTLS` handshake
Low
CVE-2026-7666
was published
for
django
(pip)
Jun 3, 2026
daphne: WebSocket handshake header smuggling through autobahn splitlines() mishandling of non-standard line separators
Low
CVE-2026-44546
was published
for
daphne
(pip)
Jun 3, 2026
Code Index MCP is vulnerable to Uncontrolled Resource Consumption
Low
CVE-2026-10692
was published
for
code-index-mcp
(pip)
Jun 3, 2026
hermes-agent has an Injection issue
Low
CVE-2026-10222
was published
for
hermes-agent
(pip)
Jun 1, 2026
Apache Airflow has an Incorrect Authorization issue
Low
CVE-2026-45426
was published
for
apache-airflow
(pip)
Jun 1, 2026
Apache Airflow has an Improper Authorization issue
Low
CVE-2026-40963
was published
for
apache-airflow
(pip)
Jun 1, 2026
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
Low
CVE-2026-10566
was published
for
metagpt
(pip)
Jun 2, 2026
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
Low
CVE-2026-10300
was published
for
sglang
(pip)
Jun 2, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Low
CVE-2026-10212
was published
for
AstrBot
(pip)
Jun 1, 2026
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
Low
CVE-2026-10177
was published
for
aider-chat
(pip)
May 31, 2026
Aider is vulnerable to Code Injection via editor_coder.run function
Low
CVE-2026-10175
was published
for
aider-chat
(pip)
May 31, 2026
ProTip!
Advisories are also available from the
GraphQL API