GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
6,272 advisories
Filter by severity
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Critical
CVE-2026-59163
was published
for
mnemosyne-memory
(pip)
Sep 18, 2026
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
High
CVE-2026-63349
was published
for
anyio
(pip)
Sep 18, 2026
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
Critical
CVE-2026-63374
was published
for
anyio
(pip)
Sep 18, 2026
AnyIO process-pool workers can block indefinitely on undrained stderr
Moderate
CVE-2026-64847
was published
for
anyio
(pip)
Sep 18, 2026
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
High
CVE-2026-33625
was published
for
lmdeploy
(pip)
Sep 18, 2026
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Critical
CVE-2025-66455
was published
for
lmdeploy
(pip)
Sep 18, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Moderate
CVE-2026-86000
was published
for
soupsieve
(pip)
Sep 17, 2026
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Moderate
CVE-2026-85999
was published
for
soupsieve
(pip)
Sep 17, 2026
djust: A template binding inherits a context safety grant it never earned (XSS)
High
GHSA-xjw9-38cr-6372
was published
for
djust
(pip)
Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
High
GHSA-9395-2g46-rj3f
was published
for
djust
(pip)
Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
High
CVE-2026-86049
was published
for
jupyter_server
(pip)
Sep 17, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
Moderate
CVE-2026-77401
was published
for
AccessControl
(pip)
Sep 17, 2026
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
High
CVE-2026-76825
was published
for
RestrictedPython
(pip)
Sep 17, 2026
sanic chunked trailer request smuggling allows hidden second request execution
Moderate
CVE-2026-85078
was published
for
sanic
(pip)
Sep 17, 2026
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
Moderate
CVE-2026-62949
was published
for
asyncssh
(pip)
Sep 17, 2026
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
Moderate
CVE-2026-59823
was published
for
litellm
(pip)
Sep 17, 2026
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
Moderate
CVE-2026-57173
was published
for
vllm
(pip)
Sep 16, 2026
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
High
CVE-2026-61599
was published
for
djust
(pip)
Sep 16, 2026
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Moderate
CVE-2026-61589
was published
for
djust
(pip)
Sep 16, 2026
djust has broken object-level access control (IDOR)
High
CVE-2026-61596
was published
for
djust
(pip)
Sep 16, 2026
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
Moderate
CVE-2026-61588
was published
for
djust
(pip)
Sep 16, 2026
djust has an authorization bypass on the WebSocket/SSE mount path
Critical
CVE-2026-61594
was published
for
djust
(pip)
Sep 16, 2026
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
High
CVE-2026-61591
was published
for
djust
(pip)
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API