GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
2,307 advisories
Filter by severity
vantage6 node has an Improper Access Control issue
Moderate
CVE-2026-54533
was published
for
vantage6
(pip)
Jun 5, 2026
Vantage6: Set admin user and password from environment or configuration
Moderate
CVE-2026-54445
was published
for
vantage6
(pip)
Jun 5, 2026
sanic-cors contains an improper regular expression in the try_match() function
Moderate
CVE-2026-37737
was published
for
sanic-cors
(pip)
Jun 5, 2026
Vantage6: 2FA can be circumvented with hacked email access
Moderate
CVE-2024-27928
was published
for
vantage6
(pip)
Jun 5, 2026
OpenStack Ironic: Crafted JSON String to Certain Endpoints on the API or JSON-RPC Service May Result in Service Crash
Moderate
CVE-2026-50589
was published
for
ironic
(pip)
Jun 5, 2026
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Moderate
CVE-2026-47707
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
Strawberry GraphQL has a Circular Fragment Reference DOS
Moderate
CVE-2026-47706
was published
for
strawberry-graphql
(pip)
Jun 4, 2026
WebOb: Location header normalization during redirect leads to open redirect - again
Moderate
CVE-2026-44889
was published
for
webob
(pip)
Jun 4, 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Moderate
CVE-2026-48710
was published
for
starlette
(pip)
Jun 4, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
Moderate
CVE-2026-48681
was published
for
ironic
(pip)
Jun 4, 2026
OpenStack Ironic allows Boot Script Injection
Moderate
CVE-2026-46447
was published
for
ironic
(pip)
Jun 4, 2026
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
Moderate
CVE-2026-47265
was published
for
aiohttp
(pip)
Jun 3, 2026
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Moderate
CVE-2026-44022
was published
for
docling
(pip)
Jun 3, 2026
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Moderate
CVE-2026-44018
was published
for
docling
(pip)
Jun 3, 2026
malla: Stored XSS via Meshtastic node names in multiple frontend pages
Moderate
CVE-2026-43980
was published
for
malla
(pip)
Jun 3, 2026
AIOHTTP is Vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2026-34993
was published
for
aiohttp
(pip)
Jun 3, 2026
jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used
Moderate
CVE-2026-6657
was published
for
jupyter-server
(pip)
Jun 3, 2026
daphne: Unauthenticated attackers can cause excessive memory consumption by sending arbitrarily large WebSocket messages/frames
Moderate
CVE-2026-44545
was published
for
daphne
(pip)
Jun 3, 2026
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Moderate
CVE-2026-5422
was published
for
jupyter-server
(pip)
Jun 2, 2026
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
Moderate
CVE-2026-3198
was published
for
mlflow
(pip)
Jun 2, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Moderate
CVE-2026-8643
was published
for
pip
(pip)
Jun 1, 2026
praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
Moderate
CVE-2026-47411
was published
for
praisonai-platform
(pip)
Jun 1, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
Moderate
CVE-2026-48726
was published
for
apache-airflow
(pip)
Jun 1, 2026
Apache Airflow has no certificate validation on SMTP STARTTLS connections
Moderate
CVE-2026-49267
was published
for
apache-airflow
(pip)
Jun 1, 2026
ProTip!
Advisories are also available from the
GraphQL API