GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,148 advisories
Filter by severity
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
Moderate
CVE-2026-73557
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Moderate
CVE-2026-73556
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Moderate
CVE-2026-73555
was published
for
vllm
(pip)
Sep 4, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
Material for MkDocs: DOM XSS in search suggestions via query parameter
Moderate
CVE-2026-73295
was published
for
mkdocs-material
(pip)
Sep 3, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
Critical
CVE-2026-71428
was published
for
unstructured
(pip)
Sep 3, 2026
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
High
CVE-2026-84366
was published
for
scrapy
(pip)
Sep 2, 2026
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
High
CVE-2026-62676
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
High
CVE-2026-62677
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Critical
CVE-2026-62674
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
High
CVE-2026-62388
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Moderate
CVE-2026-63311
was published
for
nltk
(pip)
Sep 2, 2026
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
High
CVE-2026-76098
was published
for
mistune
(pip)
Sep 2, 2026
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
High
CVE-2026-82397
was published
for
tornado
(pip)
Sep 2, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
Moderate
CVE-2026-71492
was published
for
banks
(pip)
Sep 2, 2026
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
Moderate
CVE-2026-82398
was published
for
pypdf
(pip)
Sep 2, 2026
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
Moderate
CVE-2026-81722
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
Moderate
CVE-2026-81727
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
High
CVE-2026-81726
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
Moderate
CVE-2026-81723
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
Moderate
CVE-2026-12876
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
Moderate
CVE-2026-81724
was published
for
nltk
(pip)
Sep 2, 2026
pypdf: Possible long runtimes/large memory usage when retrieving outlines
Moderate
CVE-2026-84310
was published
for
pypdf
(pip)
Sep 1, 2026
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
Moderate
CVE-2026-84311
was published
for
pypdf
(pip)
Sep 1, 2026
ProTip!
Advisories are also available from the
GraphQL API