Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,148 advisories

Loading
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts Moderate
CVE-2026-73557 was published for vllm (pip) Sep 4, 2026
hexcraft-labs Credited to hexcraft-labs and jperezdealgaba jperezdealgaba jperezdealgaba
CyberKareem Credited to CyberKareem and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages Moderate
CVE-2026-73555 was published for vllm (pip) Sep 4, 2026
biecho Credited to biecho and jperezdealgaba jperezdealgaba jperezdealgaba
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
Material for MkDocs: DOM XSS in search suggestions via query parameter Moderate
CVE-2026-73295 was published for mkdocs-material (pip) Sep 3, 2026
p- Credited to p-
unstructured: Server-Side Request Forgery in the URL-based partitioning Critical
CVE-2026-71428 was published for unstructured (pip) Sep 3, 2026
hayato1121 Credited to hayato1121
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default High
CVE-2026-84366 was published for scrapy (pip) Sep 2, 2026
syncrain Credited to syncrain
aaronjmars Credited to aaronjmars
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE Critical
CVE-2026-62674 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools High
CVE-2026-62675 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
NLTK: Default ENFORCE=False Disables All pathsec Security Controls High
CVE-2026-62388 was published for nltk (pip) Sep 2, 2026
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure Moderate
CVE-2026-63311 was published for nltk (pip) Sep 2, 2026
ekaf Credited to ekaf
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown High
CVE-2026-76098 was published for mistune (pip) Sep 2, 2026
wan1yan Credited to wan1yan
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop High
CVE-2026-82397 was published for tornado (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
spbavarva Credited to spbavarva
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace Moderate
CVE-2026-82398 was published for pypdf (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y' Moderate
CVE-2026-81722 was published for nltk (pip) Sep 2, 2026
NLTK: Downloader.download follows hardlinks and overwrites outside-root files Moderate
CVE-2026-81727 was published for nltk (pip) Sep 2, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
CVE-2026-81726 was published for nltk (pip) Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` Moderate
CVE-2026-81723 was published for nltk (pip) Sep 2, 2026
ibfavas Credited to ibfavas
pypdf: Possible long runtimes/large memory usage when retrieving outlines Moderate
CVE-2026-84310 was published for pypdf (pip) Sep 1, 2026
stefan6419846 Credited to stefan6419846 and HYUNSUNG03 HYUNSUNG03 HYUNSUNG03
pypdf: Possible long runtimes/large memory usage when extracting XForm objects Moderate
CVE-2026-84311 was published for pypdf (pip) Sep 1, 2026
zikk090 Credited to zikk090 and stefan6419846 stefan6419846 stefan6419846
ProTip! Advisories are also available from the GraphQL API