GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,886
Maven
5,000+
npm
5,000+
NuGet
1,136
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
6,479 advisories
Filter by severity
WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE
High
CVE-2026-106443
was published
for
WeasyPrint
(pip)
Oct 7, 2026
Hydra logging configuration permits unsafe callable resolution
High
CVE-2026-106441
was published
for
hydra-core
(pip)
Oct 7, 2026
Hydra instantiate target blacklist bypasses permit code execution
High
CVE-2026-106442
was published
for
hydra-core
(pip)
Oct 7, 2026
Twisted: IMAP wildcardToRegexp() ReDoS
Moderate
CVE-2026-106454
was published
for
Twisted
(pip)
Oct 7, 2026
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
High
CVE-2026-105741
was published
for
langflow
(pip)
Oct 7, 2026
PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation
Critical
CVE-2026-62176
was published
for
PraisonAI
(pip)
Oct 7, 2026
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues
Moderate
CVE-2026-62179
was published
for
praisonai-platform
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
High
CVE-2026-61436
was published
for
praisonai
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
High
CVE-2026-61428
was published
for
praisonai
(pip)
Oct 7, 2026
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry
Moderate
CVE-2026-46438
was published
for
wger
(pip)
Oct 7, 2026
wger: Trainer Privilege Escalation - Improper Privilege Management
High
CVE-2026-46434
was published
for
wger
(pip)
Oct 7, 2026
wger: API credentials remain valid after logout/password change
Moderate
CVE-2026-46437
was published
for
wger
(pip)
Oct 7, 2026
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
Moderate
CVE-2026-45161
was published
for
wger
(pip)
Oct 7, 2026
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
High
CVE-2026-43976
was published
for
wger
(pip)
Oct 7, 2026
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
High
CVE-2026-105801
was published
for
openapi-python-client
(pip)
Oct 6, 2026
Vyper: Memory corruption using function calls within tuples / nested calls
Moderate
GHSA-2r3x-4mrv-mcxf
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument
Moderate
GHSA-4v7v-gqf9-ww2g
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Return inside for loop more than 1 level deep
Moderate
GHSA-vg88-3v92-rjx2
was published
for
vyper
(pip)
Oct 6, 2026
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
CVE-2026-105747
was published
for
docling
(pip)
Oct 6, 2026
Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)
Moderate
GHSA-j8f7-x8jm-wmm4
was published
for
langflow
(pip)
Oct 6, 2026
Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
Critical
CVE-2026-10561
was published
for
langflow
(pip)
Oct 6, 2026
Duplicate Advisory: Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
GHSA-f4ch-vxwc-3p2m
was published
for
docling
(pip)
Oct 6, 2026
•
withdrawn
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Moderate
CVE-2026-105750
was published
for
docling
(pip)
Oct 6, 2026
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Moderate
CVE-2026-105753
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Low
CVE-2026-105752
was published
for
vllm
(pip)
Oct 6, 2026
ProTip!
Advisories are also available from the
GraphQL API