GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36,440 advisories
Filter by severity
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
Low
CVE-2026-105799
was published
for
@langchain/redis
(npm)
Oct 6, 2026
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
High
CVE-2026-26287
was published
for
github.com/external-secrets/external-secrets
(Go)
Oct 6, 2026
Vyper: Memory corruption using function calls within tuples / nested calls
Moderate
GHSA-2r3x-4mrv-mcxf
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument
Moderate
GHSA-4v7v-gqf9-ww2g
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Return inside for loop more than 1 level deep
Moderate
GHSA-vg88-3v92-rjx2
was published
for
vyper
(pip)
Oct 6, 2026
sharp : Vulnerability in librsvg dependency CVE-2026-96889
High
GHSA-wq5f-xc86-pv6w
was published
for
sharp
(npm)
Oct 6, 2026
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
CVE-2026-105747
was published
for
docling
(pip)
Oct 6, 2026
shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token
Critical
CVE-2026-102422
was published
for
shell-quote
(npm)
Oct 6, 2026
pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Moderate
CVE-2026-102414
was published
for
pbkdf2
(npm)
Oct 6, 2026
Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)
Moderate
GHSA-j8f7-x8jm-wmm4
was published
for
langflow
(pip)
Oct 6, 2026
Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
Critical
CVE-2026-10561
was published
for
langflow
(pip)
Oct 6, 2026
Duplicate Advisory: Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
GHSA-f4ch-vxwc-3p2m
was published
for
docling
(pip)
Oct 6, 2026
•
withdrawn
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Moderate
CVE-2026-105750
was published
for
docling
(pip)
Oct 6, 2026
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Moderate
CVE-2026-105753
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Low
CVE-2026-105752
was published
for
vllm
(pip)
Oct 6, 2026
Werkzeug safe_join() allows Windows special device names
Moderate
CVE-2026-102598
was published
for
Werkzeug
(pip)
Oct 5, 2026
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
Critical
CVE-2026-102829
was published
for
@simple-git/argv-parser
(npm)
Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration
Critical
CVE-2026-102828
was published
for
simple-git
(npm)
Oct 5, 2026
simple-git allows command execution through unblocked Git configuration includes
High
CVE-2026-102826
was published
for
simple-git
(npm)
Oct 5, 2026
simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
High
CVE-2026-102827
was published
for
simple-git
(npm)
Oct 5, 2026
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
High
CVE-2026-96749
was published
for
pymongo
(pip)
Oct 5, 2026
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
High
CVE-2026-96748
was published
for
pymongo
(pip)
Oct 5, 2026
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
Moderate
CVE-2026-96747
was published
for
pymongo
(pip)
Oct 5, 2026
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
High
CVE-2026-102600
was published
for
@socket.io/cluster-engine
(npm)
Oct 5, 2026
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
Moderate
CVE-2026-104181
was published
for
filament/filament
(Composer)
Oct 5, 2026
ProTip!
Advisories are also available from the
GraphQL API