Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
LangSmith SDK TracingMiddleware: Arbitrary server-side file read High
GHSA-f4xh-w4cj-qxq8 was published for langsmith (pip) Jun 19, 2026
ryu7eroo Credited to ryu7eroo
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean High
CVE-2026-40683 was published for keystone (pip) Apr 14, 2026
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter High
CVE-2025-22153 was published for RestrictedPython (pip) Jan 23, 2025
icemac Credited to icemac, Nico-Posada, dataflake, and tseaver Nico-Posada Nico-Posada
dataflake dataflake tseaver tseaver
Vulnerable OpenSSL included in cryptography wheels High
CVE-2023-0286 was published for cryptography (pip) Feb 8, 2023
ehe9991 Credited to ehe9991
`CHECK`-failures in Tensorflow High
CVE-2022-21734 was published for tensorflow (pip) Feb 10, 2022
Type confusion leading to segfault in Tensorflow High
CVE-2022-21731 was published for tensorflow (pip) Feb 10, 2022
ProTip! Advisories are also available from the GraphQL API