GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
4,317 advisories
Filter by severity
Hugging Face Text Generation Inference vulnerable to Uncontrolled Resource Consumption
High
CVE-2026-0599
was published
for
text-generation
(pip)
Feb 2, 2026
Lollms has an Improper Access Control vulnerability
High
CVE-2026-1117
was published
for
lollms
(pip)
Feb 2, 2026
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
High
CVE-2025-62348
was published
for
salt
(pip)
Jan 30, 2026
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
High
CVE-2025-62349
was published
for
salt
(pip)
Jan 30, 2026
geopandas SQL Injection Vulnerability in to_postgis() Allows Information Disclosure
High
CVE-2025-69662
was published
for
geopandas
(pip)
Jan 30, 2026
CAI find_file Agent Tool has Command Injection Vulnerability Through Argument Injection
Critical
CVE-2026-25130
was published
for
cai-framework
(pip)
Jan 30, 2026
Llama Stack exposes secret in initialization log
Low
CVE-2026-25211
was published
for
llama-stack
(pip)
Jan 30, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
GHSA-vg9h-jx4v-cwx2
was published
for
dfir-unfurl
(pip)
Jan 29, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
Moderate
GHSA-h5qv-qjv4-pc5m
was published
for
dfir-unfurl
(pip)
Jan 29, 2026
AutoGPT is Vulnerable to RCE via Disabled Block Execution
High
CVE-2026-24780
was published
for
agpt
(pip)
Jan 29, 2026
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
High
CVE-2026-24779
was published
for
vllm
(pip)
Jan 28, 2026
TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF)
Moderate
GHSA-gpx9-96j6-pp87
was published
for
agentos-taskweaver
(pip)
Jan 28, 2026
PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
High
CVE-2026-24747
was published
for
pytorch
(pip)
Jan 27, 2026
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
Moderate
CVE-2026-23892
was published
for
OctoPrint
(pip)
Jan 27, 2026
askbot inexhaustive permissions check allows any user to modify a different user's profile picture
Moderate
CVE-2026-1213
was published
for
askbot
(pip)
Jan 27, 2026
pypdf has possible Infinite Loop when processing outlines/bookmarks
Moderate
CVE-2026-24688
was published
for
pypdf
(pip)
Jan 26, 2026
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
High
CVE-2026-24490
was published
for
mobsf
(pip)
Jan 26, 2026
Gakido vulnerable to HTTP Header Injection (CRLF Injection)
Moderate
CVE-2026-24489
was published
for
gakido
(pip)
Jan 26, 2026
Python-Multipart has Arbitrary File Write via Non-Default Configuration
High
CVE-2026-24486
was published
for
python-multipart
(pip)
Jan 26, 2026
sigstore CSRF possibility in OIDC authentication during signing
Low
CVE-2026-24408
was published
for
sigstore
(pip)
Jan 26, 2026
GI-DocGen vulnerable to Reflected XSS via unescaped query strings
Moderate
CVE-2025-11687
was published
for
gi-docgen
(pip)
Jan 26, 2026
BentoML has a Path Traversal via Bentofile Configuration
High
CVE-2026-24123
was published
for
bentoml
(pip)
Jan 26, 2026
dcap-qvl has Missing Verification for QE Identity
Critical
CVE-2026-22696
was published
for
@phala/dcap-qvl
(npm)
Jan 26, 2026
protobuf affected by a JSON recursion depth bypass
High
CVE-2026-0994
was published
for
protobuf
(pip)
Jan 23, 2026
Sentencepiece has a a heap overflow issue
High
CVE-2026-1260
was published
for
sentencepiece
(pip)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API