GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,144 advisories
Filter by severity
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
High
CVE-2026-102930
was published
for
virtualenv
(pip)
Sep 30, 2026
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
Moderate
CVE-2026-102938
was published
for
virtualenv
(pip)
Sep 30, 2026
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Moderate
CVE-2026-92081
was published
for
fastify
(npm)
Sep 30, 2026
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
Moderate
CVE-2026-103001
was published
for
PyJWT
(pip)
Sep 30, 2026
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
Moderate
GHSA-3hv7-mjh2-fv65
was published
for
tornado
(pip)
Sep 30, 2026
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
High
GHSA-chx6-46f5-w4vp
was published
for
tornado
(pip)
Sep 30, 2026
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
High
GHSA-c2m8-h5v5-343r
was published
for
tornado
(pip)
Sep 30, 2026
GitPython submodule update path traversal can write outside the repository
Moderate
GHSA-59cr-6r3x-644w
was published
for
GitPython
(pip)
Sep 30, 2026
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
Moderate
CVE-2026-93981
was published
for
hono
(npm)
Sep 30, 2026
fastify vulnerable to request body replacement via an async validation result collision
High
CVE-2026-84504
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
High
CVE-2026-76169
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
High
CVE-2026-84469
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to header validation bypass via incomplete schema case normalization
High
CVE-2026-84428
was published
for
fastify
(npm)
Sep 30, 2026
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
Moderate
CVE-2026-102820
was published
for
pageant
(Rust)
Sep 30, 2026
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
Moderate
CVE-2026-102821
was published
for
russh
(Rust)
Sep 30, 2026
Astro: Netlify Image CDN allowlist bypass enables SSRF
Moderate
CVE-2026-102983
was published
for
@astrojs/netlify
(npm)
Sep 30, 2026
Astro: Malformed port in the Host header can crash the Node adapter
High
CVE-2026-102984
was published
for
@astrojs/node
(npm)
Sep 30, 2026
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
High
CVE-2026-87819
was published
for
GitPython
(pip)
Sep 30, 2026
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
Moderate
GHSA-whh4-5q6c-9v3x
was published
for
gitpython
(pip)
Sep 30, 2026
GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
High
CVE-2026-87817
was published
for
gitpython
(pip)
Sep 30, 2026
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic
Low
CVE-2026-102822
was published
for
russh
(Rust)
Sep 30, 2026
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
High
CVE-2026-102823
was published
for
russh
(Rust)
Sep 30, 2026
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
Moderate
CVE-2026-102824
was published
for
russh
(Rust)
Sep 30, 2026
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Low
CVE-2026-102825
was published
for
russh
(Rust)
Sep 30, 2026
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Moderate
CVE-2026-84377
was published
for
litellm
(pip)
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API