GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,430
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,680
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,804 advisories
Filter by severity
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
High
CVE-2026-34589
was published
for
OpenEXR
(pip)
Apr 8, 2026
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
High
CVE-2026-34588
was published
for
OpenEXR
(pip)
Apr 8, 2026
FastFeedParser has an infinite redirect loop DoS via meta-refresh chain
High
CVE-2026-39376
was published
for
fastfeedparser
(pip)
Apr 8, 2026
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
High
GHSA-69x8-hrgq-fjj8
was published
for
litellm
(pip)
Apr 8, 2026
MONAI: Unsafe functions lead to pickle deserialization rce
High
GHSA-89gg-p5r5-q6r4
was published
for
monai
(pip)
Apr 7, 2026
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
High
CVE-2026-34444
was published
for
lupa
(pip)
Apr 7, 2026
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
High
CVE-2026-3902
was published
for
Django
(pip)
Apr 7, 2026
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
High
CVE-2026-33034
was published
for
Django
(pip)
Apr 7, 2026
PraisonAI recipe registry publish path traversal allows out-of-root file write
High
CVE-2026-39308
was published
for
PraisonAI
(pip)
Apr 6, 2026
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
High
CVE-2026-39306
was published
for
PraisonAI
(pip)
Apr 6, 2026
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
High
CVE-2026-39307
was published
for
PraisonAI
(pip)
Apr 6, 2026
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions
High
CVE-2026-35526
was published
for
strawberry-graphql
(pip)
Apr 6, 2026
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol
High
CVE-2026-35523
was published
for
strawberry-graphql
(pip)
Apr 6, 2026
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
High
CVE-2026-35464
was published
for
pyload-ng
(pip)
Apr 4, 2026
pyLoad: Improper Neutralization of Special Elements used in an OS Command
High
CVE-2026-35463
was published
for
pyload-ng
(pip)
Apr 4, 2026
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
High
CVE-2026-30762
was published
for
lightrag-hku
(pip)
Apr 4, 2026
pyLoad: SSRF in parse_urls API endpoint via unvalidated URL parameter
High
CVE-2026-35187
was published
for
pyload-ng
(pip)
Apr 4, 2026
BentoML: SSTI via Unsandboxed Jinja2 in Dockerfile Generation
High
CVE-2026-35044
was published
for
bentoml
(pip)
Apr 3, 2026
BentoML: Command Injection in cloud deployment setup script
High
CVE-2026-35043
was published
for
bentoml
(pip)
Apr 3, 2026
LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
High
CVE-2026-35029
was published
for
litellm
(pip)
Apr 3, 2026
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
High
CVE-2026-34824
was published
for
mesop
(pip)
Apr 3, 2026
OpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
High
CVE-2026-34543
was published
for
openexr
(pip)
Apr 3, 2026
OpenEXR: integer overflow to OOB write in uncompress_b44_impl()
High
CVE-2026-34544
was published
for
openexr
(pip)
Apr 3, 2026
curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)
High
CVE-2026-33752
was published
for
curl_cffi
(pip)
Apr 3, 2026
Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims
High
CVE-2026-33175
was published
for
oauthenticator
(pip)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API