GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
48
Go
3,343
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,550
Pub
12
RubyGems
1,013
Rust
1,203
Swift
51
Unreviewed advisories
All unreviewed
5,000+
381 advisories
Filter by severity
Home Assistant has stored XSS in history-graphs
Low
CVE-2026-33045
was published
for
homeassistant
(pip)
Mar 27, 2026
Home Assistant has stored XSS in Map-card through malicious device name
Low
CVE-2026-33044
was published
for
homeassistant
(pip)
Mar 27, 2026
cryptography has incomplete DNS name constraint enforcement on peer names
Low
CVE-2026-34073
was published
for
cryptography
(pip)
Mar 27, 2026
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Low
CVE-2026-29071
was published
for
open-webui
(pip)
Mar 27, 2026
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
Low
CVE-2026-4539
was published
for
Pygments
(pip)
Mar 22, 2026
Vyper's `extract32` can ready dirty memory
Low
CVE-2024-24564
was published
for
vyper
(pip)
Feb 26, 2024
MindSQL is vulnerable to Code Injection through its ask_db function
Low
CVE-2026-4506
was published
for
mindsql
(pip)
Mar 21, 2026
Vyper's `_abi_decode` vulnerable to Memory Overflow
Low
CVE-2024-26149
was published
for
vyper
(pip)
Feb 26, 2024
Stored XSS in Memray-generated HTML reports via unescaped command-line metadata
Low
CVE-2026-32722
was published
for
memray
(pip)
Mar 16, 2026
Ansible-Core vulnerable to content protections bypass
Low
CVE-2024-11079
was published
for
ansible-core
(pip)
Nov 12, 2024
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
Low
CVE-2026-27448
was published
for
pyopenssl
(pip)
Mar 16, 2026
langchain Server-Side Request Forgery vulnerability
Low
CVE-2024-0243
was published
for
langchain
(pip)
Feb 26, 2024
Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
Low
CVE-2026-32109
was published
for
copyparty
(pip)
Mar 12, 2026
Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
Low
CVE-2026-32108
was published
for
copyparty
(pip)
Mar 12, 2026
dbt-common's commonprefix() doesn't protect against path traversal
Low
CVE-2026-29790
was published
for
dbt-common
(pip)
Mar 5, 2026
Django has a Race Condition vulnerability
Low
CVE-2026-25674
was published
for
Django
(pip)
Mar 3, 2026
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Low
CVE-2026-27167
was published
for
gradio
(pip)
Mar 1, 2026
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
Low
CVE-2026-27838
was published
for
wger
(pip)
Feb 26, 2026
dbt-core's secret env vars written to package-lock.json in plaintext
Low
GHSA-j4g3-3q8x-jxqp
was published
for
dbt-core
(pip)
Dec 8, 2023
Apache Superset allows authenticated users to view sensitive data without explicit permissions
Low
CVE-2026-23983
was published
for
apache-superset
(pip)
Feb 24, 2026
datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache
Low
CVE-2026-2970
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler
Low
CVE-2026-2969
was published
for
datapizza-ai-core
(pip)
Feb 23, 2026
pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams
Low
CVE-2026-27628
was published
for
pypdf
(pip)
Feb 25, 2026
LIEF is vulnerable to segmentation fault
Low
CVE-2025-15504
was published
for
lief
(pip)
Jan 10, 2026
Flask session does not add `Vary: Cookie` header when accessed in some ways
Low
CVE-2026-27205
was published
for
flask
(pip)
Feb 19, 2026
ProTip!
Advisories are also available from the
GraphQL API