Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,374 advisories

Loading
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use High
CVE-2026-102930 was published for virtualenv (pip) Sep 30, 2026
gaborbernat Credited to gaborbernat
gaborbernat Credited to gaborbernat
tritsystem Credited to tritsystem
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS Moderate
GHSA-3hv7-mjh2-fv65 was published for tornado (pip) Sep 30, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and manus-pi manus-pi manus-pi
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and aoto-tech aoto-tech aoto-tech
Tornado: StaticFileHandler follows symlinks outside static root (path traversal) High
GHSA-c2m8-h5v5-343r was published for tornado (pip) Sep 30, 2026
Yasha-ops Credited to Yasha-ops and iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
GitPython submodule update path traversal can write outside the repository Moderate
GHSA-59cr-6r3x-644w was published for GitPython (pip) Sep 30, 2026
kta1kri Credited to kta1kri
prvazsahnazarov Credited to prvazsahnazarov and manus-use manus-use manus-use
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle Moderate
GHSA-whh4-5q6c-9v3x was published for gitpython (pip) Sep 30, 2026
kokomaru167 Credited to kokomaru167
dharanivarma Credited to dharanivarma
urllib3: Chunked Deflate streaming can enter an infinite loop Moderate
CVE-2026-97688 was published for urllib3 (pip) Sep 30, 2026
gnuletik Credited to gnuletik, illia-v, and pquentin illia-v illia-v
pquentin pquentin
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory High
CVE-2026-97689 was published for urllib3 (pip) Sep 30, 2026
pquentin Credited to pquentin and illia-v illia-v illia-v
urllib3: HTTPS proxy TLS configuration may be ignored or overridden High
CVE-2026-97687 was published for urllib3 (pip) Sep 30, 2026
dhoepp Credited to dhoepp, shazow, fuyu0425, sethmlarson, illia-v, yonatanmgr, and pquentin shazow shazow
fuyu0425 fuyu0425 sethmlarson sethmlarson illia-v illia-v yonatanmgr yonatanmgr pquentin pquentin
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. Moderate
CVE-2026-102270 was published for pyjwt (pip) Sep 30, 2026
Yanni8 Credited to Yanni8
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation High
CVE-2026-102266 was published for PyJWT (pip) Sep 29, 2026
hsnyus-09 Credited to hsnyus-09
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header Moderate
CVE-2026-102265 was published for pyJWT (pip) Sep 29, 2026
Nivid42 Credited to Nivid42
PyJWT: Non-canonical signature segments enable raw-token revocation bypass Moderate
CVE-2026-102269 was published for PyJWT (pip) Sep 29, 2026
ze3tar Credited to ze3tar
e1024x Credited to e1024x
PyJWT accepts public JWK containers as HMAC secrets High
CVE-2026-102273 was published for PyJWT (pip) Sep 29, 2026
the-vibe-dev Credited to the-vibe-dev
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
0xSmiley Credited to 0xSmiley
PyJWT BOM Bypass High
CVE-2026-102272 was published for PyJWT (pip) Sep 29, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
babakizo420 Credited to babakizo420
ProTip! Advisories are also available from the GraphQL API