GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
4,641 advisories
Filter by severity
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
High
CVE-2026-35464
was published
for
pyload-ng
(pip)
Apr 4, 2026
pyLoad: Improper Neutralization of Special Elements used in an OS Command
High
CVE-2026-35463
was published
for
pyload-ng
(pip)
Apr 4, 2026
pyLoad: SSRF filter bypass via HTTP redirect in BaseDownloader (Incomplete fix for CVE-2026-33992)
Critical
CVE-2026-35459
was published
for
pyload-ng
(pip)
Apr 4, 2026
web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling
Moderate
GHSA-5hr4-253g-cpx2
was published
for
web3
(pip)
Apr 4, 2026
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
High
CVE-2026-30762
was published
for
lightrag-hku
(pip)
Apr 4, 2026
pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter
High
CVE-2026-35187
was published
for
pyload-ng
(pip)
Apr 4, 2026
BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation
High
CVE-2026-35044
was published
for
bentoml
(pip)
Apr 3, 2026
BentoML: Command Injection in cloud deployment setup script
High
CVE-2026-35043
was published
for
bentoml
(pip)
Apr 3, 2026
LiteLLM: Authentication bypass via OIDC userinfo cache key collision
Critical
CVE-2026-35030
was published
for
litellm
(pip)
Apr 3, 2026
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
High
CVE-2026-35029
was published
for
litellm
(pip)
Apr 3, 2026
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
High
CVE-2026-34824
was published
for
mesop
(pip)
Apr 3, 2026
vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing
Moderate
CVE-2026-34755
was published
for
vllm
(pip)
Apr 3, 2026
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
Moderate
CVE-2026-34753
was published
for
vllm
(pip)
Apr 3, 2026
OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
High
CVE-2026-34543
was published
for
openexr
(pip)
Apr 3, 2026
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
High
CVE-2026-34544
was published
for
openexr
(pip)
Apr 3, 2026
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
Moderate
CVE-2026-34052
was published
for
jupyterhub-ltiauthenticator
(pip)
Apr 3, 2026
curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)
High
CVE-2026-33752
was published
for
curl_cffi
(pip)
Apr 3, 2026
JupyterHub has an Open Redirect Vulnerability
Moderate
CVE-2026-33709
was published
for
jupyterhub
(pip)
Apr 3, 2026
Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims
High
CVE-2026-33175
was published
for
oauthenticator
(pip)
Apr 3, 2026
vLLM: Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in OpenAI API Server
Moderate
CVE-2026-34756
was published
for
vllm
(pip)
Apr 3, 2026
Tornado has cookie attribute injection via .RequestHandler.set_cookie
High
CVE-2026-35536
was published
for
tornado
(pip)
Apr 3, 2026
Ajenti has an authorization bypass during custom package installation
High
CVE-2026-35175
was published
for
ajenti-panel
(pip)
Apr 3, 2026
Kedro has Arbitrary Code Execution via Malicious Logging Configuration
Critical
CVE-2026-35171
was published
for
kedro
(pip)
Apr 3, 2026
Kedro: Path Traversal in versioned dataset loading via unsanitized version string
High
CVE-2026-35167
was published
for
kedro
(pip)
Apr 3, 2026
D-Tale: Remote Code Execution through redis/shelf storage
Moderate
CVE-2026-35052
was published
for
dtale
(pip)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API