GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
4,317 advisories
Filter by severity
orjson does not limit recursion for deeply nested JSON documents
Moderate
CVE-2025-67221
was published
for
orjson
(pip)
Jan 22, 2026
Moonraker affected by LDAP search filter injection
Low
CVE-2026-24130
was published
for
moonraker
(pip)
Jan 22, 2026
Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack
High
CVE-2026-24049
was published
for
wheel
(pip)
Jan 22, 2026
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
High
CVE-2026-24009
was published
for
docling-core
(pip)
Jan 22, 2026
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection
Low
CVE-2026-23996
was published
for
fastapi-api-key
(pip)
Jan 21, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Moderate
CVE-2026-23986
was published
for
copier
(pip)
Jan 21, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
Moderate
CVE-2026-23968
was published
for
copier
(pip)
Jan 21, 2026
Tendenci Affected by Authenticated Remote Code Execution via Pickle Deserialization
Moderate
CVE-2026-23946
was published
for
tendenci
(pip)
Jan 21, 2026
vLLM affected by RCE via auto_map dynamic module loading during model initialization
High
CVE-2026-22807
was published
for
vllm
(pip)
Jan 21, 2026
ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component
Moderate
CVE-2026-23833
was published
for
esphome
(pip)
Jan 21, 2026
Swing Music has a Directory Traversal & Filesystem can be accessed by a non-admin user
Moderate
CVE-2026-23877
was published
for
swingmusic
(pip)
Jan 21, 2026
ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion
High
CVE-2026-23842
was published
for
chatterbot
(pip)
Jan 20, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
Chainlit contain a server-side request forgery (SSRF) vulnerability
High
CVE-2026-22219
was published
for
chainlit
(pip)
Jan 20, 2026
Crawl4AI is Vulnerable to Remote Code Execution in Docker API via Hooks Parameter
Critical
CVE-2026-26216
was published
for
Crawl4AI
(pip)
Jan 16, 2026
Crawl4AI Has Local File Inclusion in Docker API via file:// URLs
Critical
CVE-2026-26217
was published
for
crawl4ai
(pip)
Jan 16, 2026
pyasn1 has a DoS vulnerability in decoder
High
CVE-2026-23490
was published
for
pyasn1
(pip)
Jan 16, 2026
Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
High
CVE-2026-23535
was published
for
wlc
(pip)
Jan 16, 2026
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Moderate
CVE-2026-23528
was published
for
distributed
(pip)
Jan 16, 2026
Apache Airflow proxy credentials for various providers might leak in task logs
High
CVE-2025-68675
was published
for
apache-airflow
(pip)
Jan 16, 2026
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
High
CVE-2025-68438
was published
for
apache-airflow
(pip)
Jan 16, 2026
Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component
High
CVE-2026-0897
was published
for
keras
(pip)
Jan 15, 2026
BlackSheep's ClientSession is vulnerable to CRLF injection
Moderate
CVE-2026-22779
was published
for
blacksheep
(pip)
Jan 14, 2026
Weblate leaks information via screenshots
Low
CVE-2026-21889
was published
for
weblate
(pip)
Jan 14, 2026
Chainlit contains an authorization bypass vulnerability
Low
CVE-2025-68492
was published
for
chainlit
(pip)
Jan 14, 2026
ProTip!
Advisories are also available from the
GraphQL API