GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
750 advisories
Filter by severity
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Critical
CVE-2026-61539
was published
for
xinference
(pip)
Aug 21, 2026
surfio has an out-of-bounds read
Critical
CVE-2026-55211
was published
for
surfio
(pip)
Aug 18, 2026
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
Critical
CVE-2026-55209
was published
for
resdata
(pip)
Aug 18, 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Critical
CVE-2026-64849
was published
for
mlflow
(pip)
Aug 17, 2026
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Critical
CVE-2026-67426
was published
for
flyto-core
(pip)
Jul 30, 2026
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Critical
CVE-2026-67429
was published
for
flyto-core
(pip)
Jul 30, 2026
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Critical
CVE-2026-64825
was published
for
homeassistant
(pip)
Jul 21, 2026
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
Critical
CVE-2026-61736
was published
for
lightrag-hku
(pip)
Jul 20, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Critical
CVE-2026-61667
was published
for
DIRAC
(pip)
Jul 13, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Critical
CVE-2026-45579
was published
for
DIRAC
(pip)
Jul 13, 2026
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
Critical
CVE-2026-61459
was published
for
mcp-server-kubernetes
(pip)
Jul 10, 2026
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Critical
CVE-2026-55615
was published
for
langroid
(pip)
Jul 6, 2026
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Critical
CVE-2026-54769
was published
for
langroid
(pip)
Jul 6, 2026
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Critical
CVE-2026-54760
was published
for
langroid
(pip)
Jul 6, 2026
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
Critical
CVE-2026-52830
was published
for
fast-mcp-telegram
(pip)
Jul 2, 2026
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
Critical
CVE-2026-50027
was published
for
mcp-memory-service
(pip)
Jul 2, 2026
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
Critical
CVE-2026-49257
was published
for
mcp-pinot-server
(pip)
Jun 26, 2026
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
Critical
GHSA-98x5-vq43-vc5p
was published
for
semantic-router
(pip)
Jun 26, 2026
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Critical
CVE-2026-48797
was published
for
@mcptoolshop/backpropagate
(npm)
Jun 26, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Critical
CVE-2026-55166
was published
for
lemur
(pip)
Jun 25, 2026
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
Critical
GHSA-phv5-334h-mxcw
was published
for
motioneye
(pip)
Jun 23, 2026
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
Critical
GHSA-qxvg-h7q2-hcxh
was published
for
motioneye
(pip)
Jun 23, 2026
motionEye: Authentication possible via password hash
Critical
CVE-2026-46488
was published
for
motioneye
(pip)
Jun 22, 2026
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Critical
CVE-2026-55447
was published
for
langflow
(pip)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API