Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,440 advisories

Loading
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values Low
CVE-2026-105799 was published for @langchain/redis (npm) Oct 6, 2026
thesanjok Credited to thesanjok and shovanchakraborty shovanchakraborty shovanchakraborty
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration High
CVE-2026-26287 was published for github.com/external-secrets/external-secrets (Go) Oct 6, 2026
1seal Credited to 1seal, gusfcarvalho, and evrardj-roche gusfcarvalho gusfcarvalho
evrardj-roche evrardj-roche
Vyper: Memory corruption using function calls within tuples / nested calls Moderate
GHSA-2r3x-4mrv-mcxf was published for vyper (pip) Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument Moderate
GHSA-4v7v-gqf9-ww2g was published for vyper (pip) Oct 6, 2026
Vyper: Return inside for loop more than 1 level deep Moderate
GHSA-vg88-3v92-rjx2 was published for vyper (pip) Oct 6, 2026
iamdefinitelyahuman Credited to iamdefinitelyahuman
sharp : Vulnerability in librsvg dependency CVE-2026-96889 High
GHSA-wq5f-xc86-pv6w was published for sharp (npm) Oct 6, 2026
jonathanlotan Credited to jonathanlotan and wittjeff wittjeff wittjeff
shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token Critical
CVE-2026-102422 was published for shell-quote (npm) Oct 6, 2026
euriconicacio Credited to euriconicacio and ljharb ljharb ljharb
pbkdf2 rehashes long passwords on every iteration, enabling denial of service Moderate
CVE-2026-102414 was published for pbkdf2 (npm) Oct 6, 2026
ljharb Credited to ljharb
andifilhohub Credited to andifilhohub and erichare erichare erichare
XlabAITeam Credited to XlabAITeam, andifilhohub, and erichare andifilhohub andifilhohub
erichare erichare
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode Moderate
CVE-2026-105750 was published for docling (pip) Oct 6, 2026
priyankn Credited to priyankn and DavidCarliez DavidCarliez DavidCarliez
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
Werkzeug safe_join() allows Windows special device names Moderate
CVE-2026-102598 was published for Werkzeug (pip) Oct 5, 2026
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection Critical
CVE-2026-102829 was published for @simple-git/argv-parser (npm) Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration Critical
CVE-2026-102828 was published for simple-git (npm) Oct 5, 2026
sec-reex Credited to sec-reex
simple-git allows command execution through unblocked Git configuration includes High
CVE-2026-102826 was published for simple-git (npm) Oct 5, 2026
bhaswanthc Credited to bhaswanthc and NotAFlightRisk NotAFlightRisk NotAFlightRisk
anir0y Credited to anir0y, bilguunbicktivism, cruzryan, the-vibe-dev, D7EAD, dellalibera, gdegrange, b1ue0ceanRun, internetteletubbie, and arundr0id bilguunbicktivism bilguunbicktivism
cruzryan cruzryan the-vibe-dev the-vibe-dev D7EAD D7EAD dellalibera dellalibera gdegrange gdegrange b1ue0ceanRun b1ue0ceanRun internetteletubbie internetteletubbie arundr0id arundr0id
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup High
CVE-2026-102600 was published for @socket.io/cluster-engine (npm) Oct 5, 2026
manus-use Credited to manus-use
Filament: Multi-factor authentication (app) management actions do not require password reauthentication Moderate
CVE-2026-104181 was published for filament/filament (Composer) Oct 5, 2026
Yezper Credited to Yezper and danharrin danharrin danharrin
ProTip! Advisories are also available from the GraphQL API