GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,943 advisories
Filter by severity
Apache Superset data query improperly discloses database schema information to low-privileged guest user
Moderate
CVE-2025-55673
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Moderate
CVE-2025-55675
was published
for
apache-superset
(pip)
Aug 14, 2025
Pillow Uncontrolled Resource Consumption
High
CVE-2021-27922
was published
for
pillow
(pip)
Mar 18, 2021
Pillow Denial of Service by Uncontrolled Resource Consumption
High
CVE-2021-27921
was published
for
Pillow
(pip)
Mar 18, 2021
Pillow Denial of Service by Uncontrolled Resource Consumption
High
CVE-2021-27923
was published
for
pillow
(pip)
Mar 18, 2021
Copier's safe template has filesystem write access outside destination path
Moderate
CVE-2025-55214
was published
for
copier
(pip)
Aug 18, 2025
Copier's safe template has arbitrary filesystem read/write access
High
CVE-2025-55201
was published
for
copier
(pip)
Aug 18, 2025
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
High
CVE-2025-9141
was published
for
vllm
(pip)
Aug 21, 2025
vllm API endpoints vulnerable to Denial of Service Attacks
High
CVE-2025-48956
was published
for
vllm
(pip)
Aug 21, 2025
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
High
CVE-2025-57751
was published
for
pyload-ng
(pip)
Aug 21, 2025
Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
Moderate
GHSA-4r9r-ch6f-vxmx
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get
Moderate
GHSA-86cj-95qr-2p4f
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression
Moderate
GHSA-f4x7-rfwp-v3xw
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
Moderate
GHSA-f745-w6jp-hpxx
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers
Moderate
GHSA-h3qp-7fh3-f8h4
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Moderate
GHSA-vr7h-p6mm-wpmh
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Moderate
GHSA-vv6j-3g6g-2pvj
was published
for
picklescan
(pip)
Aug 22, 2025
Python-Future Module Arbitrary Code Execution via Unintended Import of test.py
High
CVE-2025-50817
was published
for
future
(pip)
Aug 14, 2025
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
High
CVE-2025-57760
was published
for
langflow
(pip)
Aug 25, 2025
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
Moderate
GHSA-63cx-g855-hvv4
was published
for
mitmproxy
(pip)
Aug 25, 2025
Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers
High
CVE-2021-22570
was published
for
Google.Protobuf
(Composer)
Jan 27, 2022
•
withdrawn
h2 allows HTTP Request Smuggling due to illegal characters in headers
Moderate
CVE-2025-57804
was published
for
h2
(pip)
Aug 25, 2025
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
High
CVE-2025-5302
was published
for
llama-index-core
(pip)
Aug 26, 2025
xml2rfc has an arbitrary file read vulnerability
High
GHSA-cfmv-h8fx-85m7
was published
for
xml2rfc
(pip)
Aug 26, 2025
Picklescan has a missing detection when calling built-in python trace.Trace.run
Moderate
GHSA-5qwp-399c-mjwf
was published
for
picklescan
(pip)
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API