GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,855 advisories
Filter by severity
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
High
CVE-2026-42031
was published
for
ckan
(pip)
Apr 29, 2026
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
High
CVE-2026-42352
was published
for
pygeoapi
(pip)
Apr 29, 2026
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
High
CVE-2026-42351
was published
for
pygeoapi
(pip)
Apr 29, 2026
GitPython has Command Injection via Git options bypass
High
GHSA-rpm5-65cw-6hj4
was published
for
GitPython
(pip)
Apr 25, 2026
GitPython: Unsafe option check validates multi_options before shlex.split transformation
High
GHSA-x2qx-6953-8485
was published
for
GitPython
(pip)
Apr 25, 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
High
GHSA-v4p8-mg3p-g94g
was published
for
litellm
(pip)
Apr 25, 2026
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
High
CVE-2026-41486
was published
for
ray
(pip)
Apr 24, 2026
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
High
GHSA-xqmj-j6mv-4862
was published
for
litellm
(pip)
Apr 24, 2026
InstructLab Includes Functionality from Untrusted Control Sphere
High
CVE-2026-6859
was published
for
instructlab
(pip)
Apr 22, 2026
InstructLab vulnerable to Path Traversal
High
CVE-2026-6855
was published
for
instructlab
(pip)
Apr 22, 2026
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
High
CVE-2026-41066
was published
for
lxml
(pip)
Apr 21, 2026
Glances has SSRF in IP Plugin via public_api leading to credential leakage
High
CVE-2026-35587
was published
for
glances
(pip)
Apr 21, 2026
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
High
CVE-2026-34839
was published
for
Glances
(pip)
Apr 21, 2026
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
High
CVE-2026-33626
was published
for
lmdeploy
(pip)
Apr 21, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
High
CVE-2026-32228
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow allows code execution through crafted XCom payloads
High
CVE-2026-25917
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
pretalx vulnerable to stored cross-site scripting in organizer search typeahead
High
CVE-2026-41241
was published
for
pretalx
(pip)
Apr 18, 2026
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
High
CVE-2026-41490
was published
for
dagster
(pip)
Apr 18, 2026
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
High
CVE-2026-41496
was published
for
praisonai
(pip)
Apr 17, 2026
Weblate: Privilege escalation in the user API endpoint
High
CVE-2026-34393
was published
for
weblate
(pip)
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
High
CVE-2026-34242
was published
for
weblate
(pip)
Apr 16, 2026
Weblate: Remote code execution during backup restoration
High
CVE-2026-33435
was published
for
weblate
(pip)
Apr 16, 2026
Apache Airflow: RCE by race condition in example_xcom dag
High
CVE-2025-54550
was published
for
apache-airflow
(pip)
Apr 16, 2026
wger has Broken Access Control in Global Gym Configuration Update Endpoint
High
CVE-2026-40474
was published
for
wger
(pip)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API