GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
67 advisories
Filter by severity
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Moderate
CVE-2026-70488
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
High
CVE-2026-52869
was published
for
mcp
(pip)
Jul 16, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
Critical
CVE-2026-55166
was published
for
lemur
(pip)
Jun 25, 2026
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
High
GHSA-xhv3-q4xx-349r
was published
for
stigmem-node
(pip)
Jun 19, 2026
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
High
GHSA-x26h-xmv8-gxf7
was published
for
stigmem-node
(pip)
Jun 19, 2026
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
High
CVE-2026-55255
was published
for
langflow
(pip)
Jun 19, 2026
praisonai-platform: Authorization Bypass Through User-Controlled Key
Moderate
GHSA-2fjj-qqg8-fg7x
was published
for
praisonai-platform
(pip)
Jun 18, 2026
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Moderate
CVE-2026-54016
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Moderate
CVE-2026-54015
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Forged chat-file link allows cross-user file read and deletion
High
CVE-2026-54010
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
Moderate
CVE-2026-54009
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Moderate
CVE-2026-54006
was published
for
open-webui
(pip)
Jun 17, 2026
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
High
CVE-2026-33760
was published
for
langflow
(pip)
Jun 16, 2026
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
Low
CVE-2026-47716
was published
for
bugsink
(pip)
Jun 5, 2026
Bugsink: Issue event views can show an event from another project if its UUID is known
Low
CVE-2026-47715
was published
for
bugsink
(pip)
Jun 5, 2026
praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
High
CVE-2026-47419
was published
for
praisonai-platform
(pip)
Jun 5, 2026
praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
High
CVE-2026-47415
was published
for
praisonai-platform
(pip)
Jun 1, 2026
praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
High
CVE-2026-47417
was published
for
praisonai-platform
(pip)
Jun 1, 2026
praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
High
CVE-2026-47418
was published
for
praisonai-platform
(pip)
Jun 1, 2026
Apache Airflow has an Authorization Bypass Through User-Controlled Key
Moderate
CVE-2026-46764
was published
for
apache-airflow
(pip)
Jun 1, 2026
Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
High
CVE-2026-41084
was published
for
apache-airflow
(pip)
Jun 1, 2026
praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
High
CVE-2026-47414
was published
for
praisonai-platform
(pip)
May 29, 2026
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
High
CVE-2026-47406
was published
for
praisonai-platform
(pip)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API