GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
528 advisories
Filter by severity
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Low
CVE-2026-45316
was published
for
open-webui
(pip)
May 14, 2026
dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
Low
CVE-2026-44970
was published
for
dbt-mcp
(pip)
May 14, 2026
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
Low
CVE-2026-44969
was published
for
dbt-mcp
(pip)
May 14, 2026
OSGeo gdal has a heap-based buffer overflow
Low
CVE-2026-8212
was published
for
GDAL
(pip)
May 10, 2026
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
OSGeo GDAL vulnerable to out-of-bounds read
Low
CVE-2026-8088
was published
for
GDAL
(pip)
May 7, 2026
OSGeo GDAL vulnerable to heap-based buffer overflow
Low
CVE-2026-8087
was published
for
GDAL
(pip)
May 7, 2026
aiograpi has dependency on vulnerable orjson 3.11.4 (CVE-2025-67221)
Low
GHSA-7mw3-79jq-xc7f
was published
for
aiograpi
(pip)
May 6, 2026
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Low
CVE-2026-42448
was published
for
magic-wormhole
(pip)
May 6, 2026
Paramiko rsakey.py allows the SHA-1 algorithm
Low
CVE-2026-44405
was published
for
paramiko
(pip)
May 6, 2026
ciguard: Web UI is missing HTTP defence-in-depth headers
Low
GHSA-7ww3-xvf5-cxwm
was published
for
ciguard
(pip)
May 5, 2026
ciguard: discover_pipeline_files follows symlinks out of scan root
Low
CVE-2026-44220
was published
for
ciguard
(pip)
May 5, 2026
ciguard: Container image runs as root (no USER directive)
Low
CVE-2026-44218
was published
for
ciguard
(pip)
May 5, 2026
Microdot has HTTP response splitting in Response.set_cookie()
Low
CVE-2026-42874
was published
for
microdot
(pip)
May 5, 2026
Langchain-Chatchat Uses Insufficiently Random Values
Low
CVE-2026-7847
was published
for
langchain-chatchat
(pip)
May 5, 2026
Django Uses Cache Containing Sensitive Information
Low
CVE-2026-6907
was published
for
Django
(pip)
May 5, 2026
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API
Low
CVE-2026-7846
was published
for
langchain-chatchat
(pip)
May 5, 2026
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
Low
CVE-2026-7845
was published
for
langchain-chatchat
(pip)
May 5, 2026
Django Uses Persistent Cookies Containing Sensitive Information
Low
CVE-2026-35192
was published
for
Django
(pip)
May 5, 2026
Prefect Git Argument Injection in GitRepository Pull Steps
Low
CVE-2026-7725
was published
for
prefect
(pip)
May 4, 2026
Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
Low
CVE-2026-7724
was published
for
prefect
(pip)
May 4, 2026
mem0ai mem0 has an Improper Input Validation Issue
Low
CVE-2026-7597
was published
for
mem0ai
(pip)
May 2, 2026
django-mdeditor is Missing Authentication for Critical Function
Low
CVE-2025-13030
was published
for
django-mdeditor
(pip)
Apr 30, 2026
auto-favicon has a Server-Side Request Forgery issue
Low
CVE-2026-7150
was published
for
auto-favicon
(pip)
Apr 27, 2026
vLLM makes Use of Uninitialized Resource
Low
CVE-2026-7141
was published
for
vllm
(pip)
Apr 27, 2026
ProTip!
Advisories are also available from the
GraphQL API