GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,300 advisories
Filter by severity
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
High
CVE-2026-67422
was published
for
pymdown-extensions
(pip)
Aug 7, 2026
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
High
GHSA-wvpp-8hx9-p66j
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
High
GHSA-jm78-9fvv-mhgr
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-hmq2-w58f-27jc
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
GHSA-9rj7-rf2p-w77r
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
High
GHSA-4gmw-gg2m-w46p
was published
for
GitPython
(pip)
Aug 7, 2026
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
High
CVE-2026-70494
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
High
CVE-2026-70492
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
High
CVE-2026-70486
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
High
CVE-2026-70485
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
High
CVE-2026-70482
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
High
CVE-2026-70479
was published
for
open-webui
(pip)
Aug 4, 2026
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
High
CVE-2026-69249
was published
for
cryptography
(pip)
Aug 3, 2026
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
High
CVE-2026-69247
was published
for
cryptography
(pip)
Aug 3, 2026
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
High
CVE-2026-69244
was published
for
aiohttp
(pip)
Aug 3, 2026
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
High
GHSA-3f7w-8rr8-f37f
was published
for
GitPython
(pip)
Aug 3, 2026
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
High
CVE-2026-53502
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
High
CVE-2026-53505
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
High
CVE-2026-53504
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
High
CVE-2026-53503
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
High
CVE-2026-53501
was published
for
thumbor
(pip)
Jul 31, 2026
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
High
CVE-2026-53500
was published
for
thumbor
(pip)
Jul 31, 2026
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
High
CVE-2026-12075
was published
for
nltk
(pip)
Jul 31, 2026
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
High
CVE-2026-12061
was published
for
nltk
(pip)
Jul 31, 2026
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
High
CVE-2026-12072
was published
for
nltk
(pip)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API