GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35 advisories
Filter by severity
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
High
CVE-2026-67427
was published
for
flyto-core
(pip)
Jul 30, 2026
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
High
CVE-2026-44338
was published
for
PraisonAI
(pip)
May 11, 2026
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
High
CVE-2026-44552
was published
for
open-webui
(pip)
May 8, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Low
CVE-2026-32690
was published
for
apache-airflow
(pip)
Apr 18, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Moderate
CVE-2026-30912
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow has an authorization bypass in DagRun wait endpoint
Moderate
CVE-2026-34538
was published
for
apache-airflow
(pip)
Apr 9, 2026
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Moderate
CVE-2026-56078
was published
for
praisonaiagents
(pip)
Apr 8, 2026
Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
High
CVE-2026-28779
was published
for
apache-airflow
(pip)
Mar 17, 2026
Skill-scanner Unsecured Network Binding Vulnerability
Moderate
CVE-2026-26057
was published
for
cisco-ai-skill-scanner
(pip)
Feb 17, 2026
Agno session state overwrites between different sessions/users
High
CVE-2025-64168
was published
for
agno
(pip)
Oct 31, 2025
TigerVNC accessible via the network and not just via a UNIX socket as intended
Critical
CVE-2025-32428
was published
for
jupyter-remote-desktop-proxy
(pip)
Apr 12, 2025
nbgrader's `frame-ancestors: self` grants all users access to formgrader
High
CVE-2025-23205
was published
for
nbgrader
(pip)
Jan 17, 2025
DIRAC: Unauthorized users can read proxy contents during generation
High
CVE-2024-29905
was published
for
DIRAC
(pip)
Apr 9, 2024
Apache Airflow: DAG Code and Import Error Permissions Ignored
Moderate
CVE-2024-27906
was published
for
apache-airflow
(pip)
Feb 29, 2024
Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere
Moderate
CVE-2023-48291
was published
for
apache-airflow
(pip)
Dec 21, 2023
Apache Airflow vulnerable to privilege escalation
Moderate
CVE-2023-42792
was published
for
apache-airflow
(pip)
Oct 14, 2023
Apache Superset has Improper Access Control
Moderate
CVE-2022-45438
was published
for
apache-superset
(pip)
Jan 16, 2023
Temporary File Information Disclosure vulnerability in MPXJ
Low
CVE-2022-41954
was published
for
mpxj
(Maven)
Nov 28, 2022
Workers for local Dask clusters mistakenly listened on public interfaces
Critical
CVE-2021-42343
was published
for
distributed
(pip)
Jul 15, 2022
Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
Moderate
CVE-2022-30187
was published
for
Azure.Storage.Blobs
(Maven)
Jul 13, 2022
Use of insecure temporary file in Horovod
High
CVE-2022-0315
was published
for
horovod
(pip)
Mar 29, 2022
Exposure of Sensitive Information to an Unauthorized Actor in OpenStack tripleo-heat-templates
Moderate
CVE-2021-4180
was published
for
tripleo-heat-templates
(pip)
Mar 24, 2022
ProTip!
Advisories are also available from the
GraphQL API