GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
6,374 advisories
Filter by severity
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
High
CVE-2026-77257
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
High
CVE-2026-77243
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
High
CVE-2026-77255
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
High
CVE-2026-77253
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
High
CVE-2026-77251
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
High
CVE-2026-77246
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
High
CVE-2026-77248
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
Moderate
CVE-2026-65829
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
MPXJ: XXE Vulnerability in MerlinReader
High
CVE-2026-61570
was published
for
MPXJ.Net
(RubyGems)
Sep 22, 2026
wlc may disclose API tokens to project-configured URLs
Low
CVE-2026-62364
was published
for
wlc
(pip)
Sep 22, 2026
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
Moderate
CVE-2026-62282
was published
for
opencve
(pip)
Sep 22, 2026
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
High
CVE-2026-59991
was published
for
psd-tools
(pip)
Sep 22, 2026
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Critical
CVE-2026-59163
was published
for
mnemosyne-memory
(pip)
Sep 18, 2026
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
High
CVE-2026-63349
was published
for
anyio
(pip)
Sep 18, 2026
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
Critical
CVE-2026-63374
was published
for
anyio
(pip)
Sep 18, 2026
AnyIO process-pool workers can block indefinitely on undrained stderr
Moderate
CVE-2026-64847
was published
for
anyio
(pip)
Sep 18, 2026
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
High
CVE-2026-33625
was published
for
lmdeploy
(pip)
Sep 18, 2026
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Critical
CVE-2025-66455
was published
for
lmdeploy
(pip)
Sep 18, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Moderate
CVE-2026-86000
was published
for
soupsieve
(pip)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Moderate
CVE-2026-85999
was published
for
soupsieve
(pip)
Sep 17, 2026
djust: A template binding inherits a context safety grant it never earned (XSS)
High
GHSA-xjw9-38cr-6372
was published
for
djust
(pip)
Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
High
GHSA-9395-2g46-rj3f
was published
for
djust
(pip)
Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
ProTip!
Advisories are also available from the
GraphQL API