Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,300 advisories

Loading
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
manus-use Credited to manus-use
manus-use Credited to manus-use
tinyb0y Credited to tinyb0y
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
legobattman Credited to legobattman and Classic298 Classic298 Classic298
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages High
CVE-2026-70492 was published for open-webui (pip) Aug 4, 2026
maxntv Credited to maxntv and Classic298 Classic298 Classic298
manus-use Credited to manus-use and Classic298 Classic298 Classic298
tonghuaroot Credited to tonghuaroot and Classic298 Classic298 Classic298
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client High
CVE-2026-70482 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
edwardav970 Credited to edwardav970 and Classic298 Classic298 Classic298
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building High
CVE-2026-69249 was published for cryptography (pip) Aug 3, 2026
sjudson Credited to sjudson and woodruffw woodruffw woodruffw
X1AOxiang Credited to X1AOxiang
agners Credited to agners and bdraco bdraco bdraco
Thumbor has path traversal via post-validation URL decoding bypass in file_loader High
CVE-2026-53502 was published for thumbor (pip) Jul 31, 2026
q1uf3ng Credited to q1uf3ng and 0xHunSec 0xHunSec 0xHunSec
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS High
CVE-2026-53505 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter High
CVE-2026-53504 was published for thumbor (pip) Jul 31, 2026
geraldino2 Credited to geraldino2
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS High
CVE-2026-53503 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature High
CVE-2026-53501 was published for thumbor (pip) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex High
CVE-2026-12061 was published for nltk (pip) Jul 31, 2026
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
ProTip! Advisories are also available from the GraphQL API