GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
711 advisories
Filter by severity
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Moderate
CVE-2026-1323
was published
for
cpsit/typo3-mailqueue
(Composer)
Mar 18, 2026
Apache Spark: Spark History Server Code Execution Vulnerability
High
CVE-2025-54920
was published
for
org.apache.spark:spark-core_2.10
(Maven)
Mar 16, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
High
CVE-2026-3989
was published
for
sglang
(pip)
Mar 12, 2026
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
Critical
CVE-2026-3059
was published
for
sglang
(pip)
Mar 12, 2026
SGLang's encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module
Critical
CVE-2026-3060
was published
for
sglang
(pip)
Mar 12, 2026
LangGraph checkpoint loading has unsafe msgpack deserialization
Moderate
CVE-2026-28277
was published
for
langgraph
(pip)
Mar 5, 2026
Concrete CMS vulnerable to Remote Code Execution by stored PHP object injection
High
CVE-2026-3452
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Qwik vulnerable to Unauthenticated RCE via server$ Deserialization
Critical
CVE-2026-27971
was published
for
@builder.io/qwik
(npm)
Mar 2, 2026
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution
Moderate
CVE-2026-27794
was published
for
langgraph-checkpoint
(pip)
Feb 25, 2026
c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString property
High
CVE-2026-27830
was published
for
com.mchange:c3p0
(Maven)
Feb 25, 2026
mchange-commons-java: Remote Code Execution via JNDI Reference Resolution
High
CVE-2026-27727
was published
for
com.mchange:mchange-commons-java
(Maven)
Feb 25, 2026
Apache Camel Deserializes Untrusted Data in its LevelDB Component
High
CVE-2026-25747
was published
for
org.apache.camel:camel-leveldb
(Maven)
Feb 23, 2026
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
Low
CVE-2026-2970
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function
Low
CVE-2026-2898
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize()
High
CVE-2026-27206
was published
for
zumba/json-serializer
(Composer)
Feb 19, 2026
NVIDIA NeMo Framework Deserializes Untrusted Data
High
CVE-2025-33253
was published
for
nemo-toolkit
(pip)
Feb 18, 2026
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution
High
CVE-2025-33245
was published
for
nemo-toolkit
(pip)
Feb 18, 2026
MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Execution
High
GHSA-r33w-fg8j-9c94
was published
for
cesargb/laravel-magiclink
(Composer)
Feb 12, 2026
DiskCache has unsafe pickle deserialization
Moderate
CVE-2025-69872
was published
for
diskcache
(pip)
Feb 11, 2026
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Critical
CVE-2026-21531
was published
for
azure-ai-language-conversations-authoring
(pip)
Feb 10, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
Critical
CVE-2026-25632
was published
for
epyt-flow
(pip)
Feb 4, 2026
Duplicate Advisory: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-8x2r-v9x5-3qgh
was published
for
pdfminer.six
(pip)
Feb 3, 2026
•
withdrawn
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
High
CVE-2025-70560
was published
for
boltz
(pip)
Feb 3, 2026
picklescan vulnerable to arbitrary file create using logging.FileHandler
Moderate
GHSA-m7j5-r2p5-c39r
was published
for
picklescan
(pip)
Feb 2, 2026
picklescan missing detection by simple obfuscation of a `builtins.eval` call
High
GHSA-9m3x-qqw2-h32h
was published
for
picklescan
(pip)
Feb 2, 2026
ProTip!
Advisories are also available from the
GraphQL API