GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
794 advisories
Filter by severity
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
Critical
CVE-2026-102268
was published
for
PyJWT
(pip)
Sep 29, 2026
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
Critical
CVE-2026-61732
was published
for
decepticon
(pip)
Sep 24, 2026
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
Critical
CVE-2026-57149
was published
for
plone.app.portlets
(pip)
Sep 23, 2026
Home Assistant: XSS in Statistics Graph Card
Critical
CVE-2026-91130
was published
for
homeassistant
(pip)
Sep 22, 2026
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
Critical
CVE-2026-85734
was published
for
lightrag-hku
(pip)
Sep 22, 2026
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
Critical
CVE-2026-77244
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Critical
CVE-2026-59163
was published
for
mnemosyne-memory
(pip)
Sep 18, 2026
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
Critical
CVE-2026-63374
was published
for
anyio
(pip)
Sep 18, 2026
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Critical
CVE-2025-66455
was published
for
lmdeploy
(pip)
Sep 18, 2026
djust has an authorization bypass on the WebSocket/SSE mount path
Critical
CVE-2026-61594
was published
for
djust
(pip)
Sep 16, 2026
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
Critical
CVE-2025-59953
was published
for
lmdeploy
(pip)
Sep 16, 2026
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Critical
CVE-2026-59178
was published
for
esphome-device-builder
(pip)
Sep 14, 2026
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Critical
CVE-2026-59151
was published
for
prowler-cloud
(pip)
Sep 11, 2026
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
Critical
CVE-2026-59971
was published
for
mysql-mcp-server
(pip)
Sep 11, 2026
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
Critical
CVE-2026-78676
was published
for
GitPython
(pip)
Sep 8, 2026
NLTK: Allowlisted pickle loaders still permit code execution in current source
Critical
CVE-2026-79657
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
Critical
CVE-2026-78683
was published
for
nltk
(pip)
Sep 8, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
Critical
CVE-2026-71428
was published
for
unstructured
(pip)
Sep 3, 2026
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Critical
CVE-2026-62674
was published
for
omnigent
(pip)
Sep 2, 2026
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
CVE-2026-79675
was published
for
nltk
(pip)
Sep 1, 2026
plone.app.event vulnerable to denial of service via iCalendar import
Critical
CVE-2026-55247
was published
for
plone.app.event
(pip)
Aug 28, 2026
plone.app.portlets vulnerable to denial of service via RSS feed portlet
Critical
CVE-2026-55248
was published
for
plone.app.portlets
(pip)
Aug 28, 2026
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
Critical
CVE-2026-37004
was published
for
litellm
(pip)
Aug 27, 2026
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Critical
GHSA-93qj-5q5v-3c2h
was published
for
pantheon-agents
(pip)
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API