GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
4,474 advisories
Filter by severity
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
High
CVE-2026-32247
was published
for
graphiti-core
(pip)
Mar 12, 2026
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
Moderate
CVE-2026-32112
was published
for
ha-mcp
(pip)
Mar 12, 2026
ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
Moderate
CVE-2026-32111
was published
for
ha-mcp
(pip)
Mar 12, 2026
Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
Low
CVE-2026-32109
was published
for
copyparty
(pip)
Mar 12, 2026
Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
Low
CVE-2026-32108
was published
for
copyparty
(pip)
Mar 12, 2026
Tornado is vulnerable to DoS due to too many multipart parts
High
CVE-2026-31958
was published
for
tornado
(pip)
Mar 12, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
High
CVE-2026-3989
was published
for
sglang
(pip)
Mar 12, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
Critical
CVE-2026-3060
was published
for
sglang
(pip)
Mar 12, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
Critical
CVE-2026-3059
was published
for
sglang
(pip)
Mar 12, 2026
Tornado has incomplete validation of cookie attributes
Moderate
GHSA-78cv-mqj4-43f7
was published
for
tornado
(pip)
Mar 11, 2026
pypdf: manipulated stream length values can exhaust RAM
Moderate
CVE-2026-31826
was published
for
pypdf
(pip)
Mar 11, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
Moderate
CVE-2026-31815
was published
for
django-unicorn
(pip)
Mar 11, 2026
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Critical
CVE-2026-27825
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
High
CVE-2026-27826
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
High
CVE-2026-26118
was published
for
@azure/mcp
(npm)
Mar 10, 2026
copyparty: volflag `nohtml` did not block javascript in svg files
Moderate
CVE-2026-30974
was published
for
copyparty
(pip)
Mar 10, 2026
Glances has SQL Injection via Process Names in TimescaleDB Export
High
CVE-2026-30930
was published
for
Glances
(pip)
Mar 9, 2026
Glances Exposes Unauthenticated Configuration Secrets
High
CVE-2026-30928
was published
for
glances
(pip)
Mar 9, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
Moderate
CVE-2026-25604
was published
for
apache-airflow-providers-amazon
(pip)
Mar 9, 2026
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
High
CVE-2025-69219
was published
for
apache-airflow-providers-http
(pip)
Mar 9, 2026
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
High
GHSA-g9rg-8vq5-mpwm
was published
for
mcp-memory-service
(pip)
Mar 7, 2026
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
High
GHSA-5r2p-pjr8-7fh7
was published
for
sagemaker
(pip)
Mar 5, 2026
Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure
High
CVE-2026-30244
was published
for
plane
(pip)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API