GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
6,374 advisories
Filter by severity
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
High
CVE-2026-102930
was published
for
virtualenv
(pip)
Sep 30, 2026
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
Moderate
CVE-2026-102938
was published
for
virtualenv
(pip)
Sep 30, 2026
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
Moderate
CVE-2026-103001
was published
for
PyJWT
(pip)
Sep 30, 2026
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
Moderate
GHSA-3hv7-mjh2-fv65
was published
for
tornado
(pip)
Sep 30, 2026
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
High
GHSA-chx6-46f5-w4vp
was published
for
tornado
(pip)
Sep 30, 2026
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
High
GHSA-c2m8-h5v5-343r
was published
for
tornado
(pip)
Sep 30, 2026
GitPython submodule update path traversal can write outside the repository
Moderate
GHSA-59cr-6r3x-644w
was published
for
GitPython
(pip)
Sep 30, 2026
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
High
CVE-2026-87819
was published
for
GitPython
(pip)
Sep 30, 2026
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
Moderate
GHSA-whh4-5q6c-9v3x
was published
for
gitpython
(pip)
Sep 30, 2026
GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
High
CVE-2026-87817
was published
for
gitpython
(pip)
Sep 30, 2026
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
Moderate
CVE-2026-84377
was published
for
litellm
(pip)
Sep 30, 2026
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
Moderate
CVE-2026-101918
was published
for
PyJWT
(pip)
Sep 30, 2026
urllib3: Chunked Deflate streaming can enter an infinite loop
Moderate
CVE-2026-97688
was published
for
urllib3
(pip)
Sep 30, 2026
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
High
CVE-2026-97689
was published
for
urllib3
(pip)
Sep 30, 2026
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
High
CVE-2026-97687
was published
for
urllib3
(pip)
Sep 30, 2026
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
Moderate
CVE-2026-102270
was published
for
pyjwt
(pip)
Sep 30, 2026
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
High
CVE-2026-102266
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
Moderate
CVE-2026-102265
was published
for
pyJWT
(pip)
Sep 29, 2026
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
Moderate
CVE-2026-102269
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
Critical
CVE-2026-102268
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT accepts public JWK containers as HMAC secrets
High
CVE-2026-102273
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: PyJWKClient follows redirects when fetching JWKS
High
CVE-2026-102267
was published
for
PyJWT
(pip)
Sep 29, 2026
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
High
CVE-2026-102271
was published
for
pyjwt
(pip)
Sep 29, 2026
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
Moderate
CVE-2026-101917
was published
for
pyjwt
(pip)
Sep 29, 2026
ProTip!
Advisories are also available from the
GraphQL API