GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
2,307 advisories
Filter by severity
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Moderate
CVE-2026-59223
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Moderate
CVE-2026-59222
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Moderate
CVE-2026-59217
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Moderate
CVE-2026-59227
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Moderate
CVE-2026-59220
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Account enumeration via observable login timing discrepancy
Moderate
CVE-2026-59218
was published
for
open-webui
(pip)
Jul 24, 2026
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
Moderate
CVE-2026-61632
was published
for
pymdown-extensions
(pip)
Jul 24, 2026
AWS CLI: Overly permissive File Permissions
Moderate
CVE-2026-13769
was published
for
awscli
(pip)
Jul 24, 2026
pypdf: Possible long runtimes for repeated malformed cross-reference entries
Moderate
CVE-2026-59937
was published
for
pypdf
(pip)
Jul 23, 2026
pypdf: Possible large memory usage for wrong image dimensions
Moderate
CVE-2026-59938
was published
for
pypdf
(pip)
Jul 23, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
GHSA-89vp-jrxv-24w8
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
Moderate
CVE-2026-59820
was published
for
litellm
(pip)
Jul 22, 2026
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Moderate
CVE-2026-59890
was published
for
setuptools
(pip)
Jul 21, 2026
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Moderate
CVE-2026-59203
was published
for
pillow
(pip)
Jul 20, 2026
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Moderate
CVE-2026-59198
was published
for
Pillow
(pip)
Jul 20, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Moderate
CVE-2026-59930
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: Arbitrary File Read via Include directive path traversal
Moderate
CVE-2026-59924
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Moderate
CVE-2026-59927
was published
for
mistune
(pip)
Jul 20, 2026
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Moderate
CVE-2026-55798
was published
for
Pillow
(pip)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API