GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
442
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
pyLoad has a Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)
Moderate
CVE-2026-40594
was published
for
pyload-ng
(pip)
Apr 16, 2026
Improper Authentication and Origin Validation Error in pyload-ng
Moderate
CVE-2026-33314
was published
for
pyload-ng
(pip)
Mar 19, 2026
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
High
CVE-2026-32634
was published
for
Glances
(pip)
Mar 16, 2026
Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
Moderate
CVE-2026-32632
was published
for
Glances
(pip)
Mar 16, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
Moderate
CVE-2026-25604
was published
for
apache-airflow-providers-amazon
(pip)
Mar 9, 2026
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
High
CVE-2025-14279
was published
for
mlflow
(pip)
Jan 12, 2026
Langflow CORS misconfiguration enables Account Takeover and RCE
Critical
CVE-2025-34291
was published
for
langflow
(pip)
Dec 6, 2025
Neo4j Cypher MCP server is vulnerable to DNS rebinding
High
CVE-2025-10193
was published
for
mcp-neo4j-cypher
(pip)
Sep 11, 2025
pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
High
CVE-2025-9636
was published
for
pgadmin4
(pip)
Sep 5, 2025
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High
CVE-2024-8487
was published
for
agentscope
(pip)
Mar 20, 2025
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
High
CVE-2024-8183
was published
for
prefect
(pip)
Mar 20, 2025
Flask-CORS allows for inconsistent CORS matching
Moderate
CVE-2024-6844
was published
for
flask-cors
(pip)
Mar 20, 2025
Feast Cross-Origin Resource Sharing vulnerability
High
CVE-2024-11602
was published
for
feast
(pip)
Mar 20, 2025
Gradio's CORS origin validation accepts the null origin
Moderate
CVE-2024-47165
was published
for
gradio
(pip)
Oct 10, 2024
Gradios's CORS origin validation is not performed when the request has a cookie
High
CVE-2024-47084
was published
for
gradio
(pip)
Oct 10, 2024
Origin Validation Error in rdiffweb
Critical
CVE-2022-3457
was published
for
rdiffweb
(pip)
Oct 14, 2022
ProTip!
Advisories are also available from the
GraphQL API