GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
465 advisories
Filter by severity
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
Low
GHSA-8rfp-98v4-mmr6
was published
for
bleach
(pip)
Jun 16, 2026
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Low
CVE-2026-54282
was published
for
Starlette
(pip)
Jun 15, 2026
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
Low
CVE-2026-53540
was published
for
python-multipart
(pip)
Jun 15, 2026
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
Low
CVE-2026-53538
was published
for
python-multipart
(pip)
Jun 15, 2026
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
Low
CVE-2026-53537
was published
for
python-multipart
(pip)
Jun 15, 2026
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
Low
CVE-2026-54275
was published
for
aiohttp
(pip)
Jun 15, 2026
aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
Low
CVE-2026-54280
was published
for
aiohttp
(pip)
Jun 15, 2026
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
Low
CVE-2026-54279
was published
for
aiohttp
(pip)
Jun 15, 2026
aiohttp: CRLF injection in multipart headers
Low
CVE-2026-50269
was published
for
aiohttp
(pip)
Jun 15, 2026
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
Low
CVE-2026-48524
was published
for
pyjwt
(pip)
Jun 15, 2026
Tornado has out-of-bounds memory access via C extension
Low
CVE-2026-49854
was published
for
tornado
(pip)
Jun 12, 2026
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
Low
CVE-2026-47712
was published
for
dulwich
(pip)
Jun 8, 2026
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known
Low
CVE-2026-47716
was published
for
bugsink
(pip)
Jun 5, 2026
Bugsink: Issue event views can show an event from another project if its UUID is known
Low
CVE-2026-47715
was published
for
bugsink
(pip)
Jun 5, 2026
Vantage6: No limit on emails sent for password/MFA reset
Low
CVE-2024-24769
was published
for
vantage6
(pip)
Jun 5, 2026
kas's late signature validation may allow unnoticed repository manipulations
Low
CVE-2026-47192
was published
for
kas
(pip)
Jun 4, 2026
kas checks out SHA-like git branches as valid commits
Low
CVE-2026-47191
was published
for
kas
(pip)
Jun 1, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Low
CVE-2026-45739
was published
for
strawberry-graphql
(pip)
May 19, 2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Low
CVE-2026-8754
was published
for
AstrBot
(pip)
May 17, 2026
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Low
CVE-2026-45316
was published
for
open-webui
(pip)
May 14, 2026
dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
Low
CVE-2026-44970
was published
for
dbt-mcp
(pip)
May 14, 2026
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
Low
CVE-2026-44969
was published
for
dbt-mcp
(pip)
May 14, 2026
OSGeo gdal has a heap-based buffer overflow
Low
CVE-2026-8212
was published
for
GDAL
(pip)
May 10, 2026
justhtml introduces denial-of-service hardening
Low
GHSA-r8cj-3554-33mr
was published
for
justhtml
(pip)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API