GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,718 advisories
Filter by severity
Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
High
CVE-2026-32634
was published
for
Glances
(pip)
Mar 16, 2026
Glances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
High
CVE-2026-32611
was published
for
Glances
(pip)
Mar 16, 2026
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
High
CVE-2026-32610
was published
for
Glances
(pip)
Mar 16, 2026
Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
High
CVE-2026-32609
was published
for
Glances
(pip)
Mar 16, 2026
Glances has a Command Injection via Process Names in Action Command Templates
High
CVE-2026-32608
was published
for
Glances
(pip)
Mar 16, 2026
Glances exposes the REST API without authentication
High
CVE-2026-32596
was published
for
Glances
(pip)
Mar 16, 2026
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
High
CVE-2026-28500
was published
for
onnx
(pip)
Mar 16, 2026
pyOpenSSL DTLS cookie callback buffer overflow
High
CVE-2026-27459
was published
for
pyopenssl
(pip)
Mar 16, 2026
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
High
CVE-2026-28498
was published
for
authlib
(pip)
Mar 16, 2026
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
High
CVE-2026-28490
was published
for
authlib
(pip)
Mar 16, 2026
FastMCP OAuth Proxy token reuse across MCP servers
High
CVE-2025-69196
was published
for
fastmcp
(pip)
Mar 16, 2026
SimpleEval: Objects (including modules) can leak dangerous modules through to direct access inside the sandbox
High
CVE-2026-32640
was published
for
simpleeval
(pip)
Mar 13, 2026
PyJWT accepts unknown `crit` header extensions
High
CVE-2026-32597
was published
for
PyJWT
(pip)
Mar 13, 2026
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
High
GHSA-cwxj-rr6w-m6w7
was published
for
Scrapy
(pip)
Mar 13, 2026
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
High
CVE-2026-31899
was published
for
CairoSVG
(pip)
Mar 13, 2026
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
High
CVE-2026-32116
was published
for
magic-wormhole
(pip)
Mar 13, 2026
Black: Arbitrary file writes from unsanitized user input in cache file name
High
CVE-2026-32274
was published
for
black
(pip)
Mar 12, 2026
multipart vulnerable to ReDoS in `parse_options_header()`
High
CVE-2026-28356
was published
for
multipart
(pip)
Mar 12, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
High
CVE-2026-32247
was published
for
graphiti-core
(pip)
Mar 12, 2026
Tornado is vulnerable to DoS due to too many multipart parts
High
CVE-2026-31958
was published
for
tornado
(pip)
Mar 12, 2026
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
High
CVE-2026-3989
was published
for
sglang
(pip)
Mar 12, 2026
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
High
CVE-2026-27826
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network
High
CVE-2026-26118
was published
for
@azure/mcp
(npm)
Mar 10, 2026
Glances has SQL Injection via Process Names in TimescaleDB Export
High
CVE-2026-30930
was published
for
Glances
(pip)
Mar 9, 2026
Glances Exposes Unauthenticated Configuration Secrets
High
CVE-2026-30928
was published
for
glances
(pip)
Mar 9, 2026
ProTip!
Advisories are also available from the
GraphQL API