Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,144 advisories

Loading
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use High
CVE-2026-102930 was published for virtualenv (pip) Sep 30, 2026
gaborbernat Credited to gaborbernat
gaborbernat Credited to gaborbernat
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses Moderate
CVE-2026-92081 was published for fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
tritsystem Credited to tritsystem
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS Moderate
GHSA-3hv7-mjh2-fv65 was published for tornado (pip) Sep 30, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and manus-pi manus-pi manus-pi
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and aoto-tech aoto-tech aoto-tech
Tornado: StaticFileHandler follows symlinks outside static root (path traversal) High
GHSA-c2m8-h5v5-343r was published for tornado (pip) Sep 30, 2026
Yasha-ops Credited to Yasha-ops and iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
GitPython submodule update path traversal can write outside the repository Moderate
GHSA-59cr-6r3x-644w was published for GitPython (pip) Sep 30, 2026
kta1kri Credited to kta1kri
hono/jsx renders plain strings unescaped in boundary components, leading to XSS Moderate
CVE-2026-93981 was published for hono (npm) Sep 30, 2026
ggmolly Credited to ggmolly
fastify vulnerable to request body replacement via an async validation result collision High
CVE-2026-84504 was published for fastify (npm) Sep 30, 2026
velgusgus599 Credited to velgusgus599, UlisesGascon, climba03003, and mcollina UlisesGascon UlisesGascon
climba03003 climba03003 mcollina mcollina
vvvvvvvvvvitel Credited to vvvvvvvvvvitel, mcollina, UlisesGascon, schecthellraiser606, and B1gN0Se mcollina mcollina
UlisesGascon UlisesGascon schecthellraiser606 schecthellraiser606 B1gN0Se B1gN0Se
fastify vulnerable to request validation bypass via skipped boolean false schemas High
CVE-2026-84469 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
fastify vulnerable to header validation bypass via incomplete schema case normalization High
CVE-2026-84428 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Guigu98 Credited to Guigu98
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey Moderate
CVE-2026-102821 was published for russh (Rust) Sep 30, 2026
Guigu98 Credited to Guigu98
Astro: Netlify Image CDN allowlist bypass enables SSRF Moderate
CVE-2026-102983 was published for @astrojs/netlify (npm) Sep 30, 2026
pacocartones Credited to pacocartones
Astro: Malformed port in the Host header can crash the Node adapter High
CVE-2026-102984 was published for @astrojs/node (npm) Sep 30, 2026
Celggar Credited to Celggar
prvazsahnazarov Credited to prvazsahnazarov and manus-use manus-use manus-use
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle Moderate
GHSA-whh4-5q6c-9v3x was published for gitpython (pip) Sep 30, 2026
kokomaru167 Credited to kokomaru167
dharanivarma Credited to dharanivarma
sonicnew Credited to sonicnew
sonicnew Credited to sonicnew
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange Moderate
CVE-2026-102824 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path Low
CVE-2026-102825 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
ProTip! Advisories are also available from the GraphQL API