Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,479 advisories

Loading
WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE High
CVE-2026-106443 was published for WeasyPrint (pip) Oct 7, 2026
svinkros Credited to svinkros
Hydra logging configuration permits unsafe callable resolution High
CVE-2026-106441 was published for hydra-core (pip) Oct 7, 2026
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
Hydra instantiate target blacklist bypasses permit code execution High
CVE-2026-106442 was published for hydra-core (pip) Oct 7, 2026
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
Twisted: IMAP wildcardToRegexp() ReDoS Moderate
CVE-2026-106454 was published for Twisted (pip) Oct 7, 2026
sharanxP Credited to sharanxP
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write High
CVE-2026-105741 was published for langflow (pip) Oct 7, 2026
erichare Credited to erichare and andifilhohub andifilhohub andifilhohub
PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation Critical
CVE-2026-62176 was published for PraisonAI (pip) Oct 7, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues Moderate
CVE-2026-62179 was published for praisonai-platform (pip) Oct 7, 2026
rexpository Credited to rexpository
rexpository Credited to rexpository
dinhvaren Credited to dinhvaren
wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.slot_entry Moderate
CVE-2026-46438 was published for wger (pip) Oct 7, 2026
KadirArslan Credited to KadirArslan
wger: Trainer Privilege Escalation - Improper Privilege Management High
CVE-2026-46434 was published for wger (pip) Oct 7, 2026
KadirArslan Credited to KadirArslan
wger: API credentials remain valid after logout/password change Moderate
CVE-2026-46437 was published for wger (pip) Oct 7, 2026
VashuVats Credited to VashuVats
wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding Moderate
CVE-2026-45161 was published for wger (pip) Oct 7, 2026
whatisproblem Credited to whatisproblem
wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) High
CVE-2026-43976 was published for wger (pip) Oct 7, 2026
whatisproblem Credited to whatisproblem
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation High
CVE-2026-105801 was published for openapi-python-client (pip) Oct 6, 2026
Gal3m Credited to Gal3m, iabdullah215, and 0xsharz iabdullah215 iabdullah215
0xsharz 0xsharz
Vyper: Memory corruption using function calls within tuples / nested calls Moderate
GHSA-2r3x-4mrv-mcxf was published for vyper (pip) Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument Moderate
GHSA-4v7v-gqf9-ww2g was published for vyper (pip) Oct 6, 2026
Vyper: Return inside for loop more than 1 level deep Moderate
GHSA-vg88-3v92-rjx2 was published for vyper (pip) Oct 6, 2026
iamdefinitelyahuman Credited to iamdefinitelyahuman
jonathanlotan Credited to jonathanlotan and wittjeff wittjeff wittjeff
andifilhohub Credited to andifilhohub and erichare erichare erichare
XlabAITeam Credited to XlabAITeam, andifilhohub, and erichare andifilhohub andifilhohub
erichare erichare
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode Moderate
CVE-2026-105750 was published for docling (pip) Oct 6, 2026
priyankn Credited to priyankn and DavidCarliez DavidCarliez DavidCarliez
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
ProTip! Advisories are also available from the GraphQL API