GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
6,462 advisories
Filter by severity
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
High
CVE-2026-105801
was published
for
openapi-python-client
(pip)
Oct 6, 2026
Vyper: Memory corruption using function calls within tuples / nested calls
Moderate
GHSA-2r3x-4mrv-mcxf
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument
Moderate
GHSA-4v7v-gqf9-ww2g
was published
for
vyper
(pip)
Oct 6, 2026
Vyper: Return inside for loop more than 1 level deep
Moderate
GHSA-vg88-3v92-rjx2
was published
for
vyper
(pip)
Oct 6, 2026
Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
CVE-2026-105747
was published
for
docling
(pip)
Oct 6, 2026
Langflow: SSRF in URL-taking components (protection disabled by default / warn-only, not applied to RSS, SearXNG, Web Search, Home Assistant, Glean, Docling)
Moderate
GHSA-j8f7-x8jm-wmm4
was published
for
langflow
(pip)
Oct 6, 2026
Langflow: PythonREPLComponent executes unsandboxed Python code, enabling authenticated RCE and privilege escalation
Critical
CVE-2026-10561
was published
for
langflow
(pip)
Oct 6, 2026
Duplicate Advisory: Docling: METS-GBS archive member limit enforced after full member enumeration (memory exhaustion during format detection)
Moderate
GHSA-f4ch-vxwc-3p2m
was published
for
docling
(pip)
Oct 6, 2026
•
withdrawn
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Moderate
CVE-2026-105750
was published
for
docling
(pip)
Oct 6, 2026
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Moderate
CVE-2026-105753
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Low
CVE-2026-105752
was published
for
vllm
(pip)
Oct 6, 2026
Werkzeug safe_join() allows Windows special device names
Moderate
CVE-2026-102598
was published
for
Werkzeug
(pip)
Oct 5, 2026
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
High
CVE-2026-96749
was published
for
pymongo
(pip)
Oct 5, 2026
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
High
CVE-2026-96748
was published
for
pymongo
(pip)
Oct 5, 2026
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
Moderate
CVE-2026-96747
was published
for
pymongo
(pip)
Oct 5, 2026
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
Moderate
CVE-2026-102275
was published
for
PyJWT
(pip)
Oct 5, 2026
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
Moderate
CVE-2026-105758
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
Moderate
CVE-2026-105760
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Moderate
CVE-2026-105754
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
Moderate
CVE-2026-105757
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Moderate
CVE-2026-105755
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Moderate
CVE-2026-105756
was published
for
vllm
(pip)
Oct 5, 2026
uv: Path traversal on Windows through wheel extraction
Moderate
CVE-2026-104843
was published
for
uv
(pip)
Oct 5, 2026
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
Moderate
CVE-2026-102991
was published
for
Mako
(pip)
Oct 5, 2026
Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction
Moderate
CVE-2026-104874
was published
for
multidict
(pip)
Oct 5, 2026
ProTip!
Advisories are also available from the
GraphQL API