GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,653
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,860
Pub
13
RubyGems
1,050
Rust
1,304
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,972 advisories
Filter by severity
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key
Moderate
GHSA-8pqq-224h-x875
was published
for
ogham-mcp
(pip)
May 5, 2026
pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification via unrestricted `ssl_verify` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
Moderate
CVE-2026-42312
was published
for
pyload-ng
(pip)
May 4, 2026
wlc: print_html outputs API data without HTML escaping
Moderate
CVE-2026-42150
was published
for
wlc
(pip)
Apr 24, 2026
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Moderate
CVE-2026-42310
was published
for
pillow
(pip)
May 4, 2026
Pillow has an integer overflow when processing fonts
Moderate
CVE-2026-42308
was published
for
pillow
(pip)
May 4, 2026
Pillow has a heap buffer overflow with nested list coordinates
Moderate
CVE-2026-42309
was published
for
pillow
(pip)
May 4, 2026
AgentScope Vulnerable to Remote Code Injection
Moderate
CVE-2026-6603
was published
for
agentscope
(pip)
Apr 20, 2026
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
Moderate
CVE-2026-42032
was published
for
ckan
(pip)
Apr 30, 2026
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Moderate
CVE-2026-41654
was published
for
weblate
(pip)
Apr 30, 2026
Weblate Doesn't Invalidate API Token on Password Change
Moderate
CVE-2026-41519
was published
for
weblate
(pip)
Apr 30, 2026
CKAN has CSRF exemption primed by anonymous requests
Moderate
CVE-2026-41255
was published
for
ckan
(pip)
Apr 29, 2026
CKAN has no certificate validation on STMP connection
Moderate
CVE-2026-41132
was published
for
ckan
(pip)
Apr 29, 2026
beets has a Cross-site Scripting vulnerability
Moderate
CVE-2026-42052
was published
for
beets
(pip)
Apr 29, 2026
AgentScope vulnerable to Server-Side Request Forgery
Moderate
CVE-2026-6606
was published
for
agentscope
(pip)
Apr 20, 2026
AgentScope vulnerable to Server-Side Request Forgery
Moderate
CVE-2026-6605
was published
for
agentscope
(pip)
Apr 20, 2026
AgentScope vulnerable to Server-Side Request Forgery
Moderate
CVE-2026-6604
was published
for
agentscope
(pip)
Apr 20, 2026
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
Moderate
CVE-2026-33866
was published
for
mlflow
(pip)
Apr 7, 2026
LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
Moderate
CVE-2026-41481
was published
for
langchain-text-splitters
(pip)
Apr 16, 2026
JupyterHub has an Open Redirect Vulnerability
Moderate
CVE-2026-33709
was published
for
jupyterhub
(pip)
Apr 3, 2026
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders
Moderate
CVE-2026-41426
was published
for
pretalx
(pip)
Apr 18, 2026
Authlib: Cross-site request forging when using cache
Moderate
CVE-2026-41425
was published
for
authlib
(pip)
Apr 16, 2026
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Moderate
CVE-2025-68463
was published
for
biopython
(pip)
Dec 18, 2025
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
Moderate
CVE-2026-40602
was published
for
homeassistant-cli
(pip)
Apr 16, 2026
pyLoad has a Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)
Moderate
CVE-2026-40594
was published
for
pyload-ng
(pip)
Apr 16, 2026
mitmproxy has an LDAP Injection
Moderate
CVE-2026-40606
was published
for
mitmproxy
(pip)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API