GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
42
Go
3,138
Maven
5,000+
npm
5,000+
NuGet
831
pip
4,438
Pub
12
RubyGems
990
Rust
1,174
Swift
50
Unreviewed advisories
All unreviewed
5,000+
4,438 advisories
Filter by severity
pypdf: manipulated stream length values can exhaust RAM
Moderate
CVE-2026-31826
was published
for
pypdf
(pip)
Mar 11, 2026
django-unicorn affected by component state manipulation via unvalidated attribute access
Moderate
CVE-2026-31815
was published
for
django-unicorn
(pip)
Mar 11, 2026
Authlib has 1-click Account Takeover vulnerability
Moderate
CVE-2025-68158
was published
for
authlib
(pip)
Jan 8, 2026
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Critical
CVE-2026-27825
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
High
CVE-2026-27826
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
copyparty: volflag `nohtml` did not block javascript in svg files
Moderate
CVE-2026-30974
was published
for
copyparty
(pip)
Mar 10, 2026
Glances has SQL Injection via Process Names in TimescaleDB Export
High
CVE-2026-30930
was published
for
Glances
(pip)
Mar 9, 2026
Glances Exposes Unauthenticated Configuration Secrets
High
CVE-2026-30928
was published
for
glances
(pip)
Mar 9, 2026
asyncmy is vulnerable to SQL injection via crafted dict keys
Critical
CVE-2025-65896
was published
for
asyncmy
(pip)
Dec 2, 2025
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
Moderate
CVE-2026-25604
was published
for
apache-airflow-providers-amazon
(pip)
Mar 9, 2026
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
High
CVE-2025-69219
was published
for
apache-airflow-providers-http
(pip)
Mar 9, 2026
mcp-memory-service Vulnerable to System Information Disclosure via Health Endpoint
Moderate
CVE-2026-29787
was published
for
mcp-memory-service
(pip)
Mar 5, 2026
pyLoad has an Arbitrary File Write via Path Traversal in edit_package()
High
CVE-2026-29778
was published
for
pyload-ng
(pip)
Mar 5, 2026
eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write
Moderate
CVE-2026-29780
was published
for
eml-parser
(pip)
Mar 5, 2026
LangGraph checkpoint loading has unsafe msgpack deserialization
Moderate
CVE-2026-28277
was published
for
langgraph
(pip)
Mar 5, 2026
Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure
High
CVE-2026-30244
was published
for
plane
(pip)
Mar 5, 2026
Plane has SSRF via Incomplete IP Validation in Webhook URL Serializer
High
CVE-2026-30242
was published
for
plane
(pip)
Mar 5, 2026
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
High
GHSA-g9rg-8vq5-mpwm
was published
for
mcp-memory-service
(pip)
Mar 7, 2026
Python-Markdown has an Uncaught Exception
Moderate
CVE-2025-69534
was published
for
Markdown
(pip)
Mar 5, 2026
dbt-common's commonprefix() doesn't protect against path traversal
Low
CVE-2026-29790
was published
for
dbt-common
(pip)
Mar 5, 2026
RAGAS has an Arbitrary File Read vulnerability
High
CVE-2025-45691
was published
for
ragas
(pip)
Mar 5, 2026
changedetection.io has Zip Slip vulnerability in the backup restore functionality
High
CVE-2026-29065
was published
for
changedetection.io
(pip)
Mar 4, 2026
changedetection.io vulnerable to XPath - Arbitrary File Read via unparsed-text()
High
CVE-2026-29039
was published
for
changedetection.io
(pip)
Mar 4, 2026
ProTip!
Advisories are also available from the
GraphQL API