Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,462 advisories

Loading
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation High
CVE-2026-105801 was published for openapi-python-client (pip) Oct 6, 2026
Gal3m Credited to Gal3m, iabdullah215, and 0xsharz iabdullah215 iabdullah215
0xsharz 0xsharz
Vyper: Memory corruption using function calls within tuples / nested calls Moderate
GHSA-2r3x-4mrv-mcxf was published for vyper (pip) Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument Moderate
GHSA-4v7v-gqf9-ww2g was published for vyper (pip) Oct 6, 2026
Vyper: Return inside for loop more than 1 level deep Moderate
GHSA-vg88-3v92-rjx2 was published for vyper (pip) Oct 6, 2026
iamdefinitelyahuman Credited to iamdefinitelyahuman
jonathanlotan Credited to jonathanlotan and wittjeff wittjeff wittjeff
andifilhohub Credited to andifilhohub and erichare erichare erichare
XlabAITeam Credited to XlabAITeam, andifilhohub, and erichare andifilhohub andifilhohub
erichare erichare
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode Moderate
CVE-2026-105750 was published for docling (pip) Oct 6, 2026
priyankn Credited to priyankn and DavidCarliez DavidCarliez DavidCarliez
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
Werkzeug safe_join() allows Windows special device names Moderate
CVE-2026-102598 was published for Werkzeug (pip) Oct 5, 2026
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion Moderate
CVE-2026-102275 was published for PyJWT (pip) Oct 5, 2026
ze3tar Credited to ze3tar
0xiviel Credited to 0xiviel and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion Moderate
CVE-2026-105760 was published for vllm (pip) Oct 5, 2026
adithyan-ak Credited to adithyan-ak and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features Moderate
CVE-2026-105754 was published for vllm (pip) Oct 5, 2026
KernelClint Credited to KernelClint and jperezdealgaba jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
uv: Path traversal on Windows through wheel extraction Moderate
CVE-2026-104843 was published for uv (pip) Oct 5, 2026
woodruffw Credited to woodruffw, charliermarsh, and White0xdi3 charliermarsh charliermarsh
White0xdi3 White0xdi3
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup Moderate
CVE-2026-102991 was published for Mako (pip) Oct 5, 2026
euriconicacio Credited to euriconicacio
Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction Moderate
CVE-2026-104874 was published for multidict (pip) Oct 5, 2026
waydeshi Credited to waydeshi
ProTip! Advisories are also available from the GraphQL API