GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,406 advisories
Filter by severity
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
High
CVE-2026-84366
was published
for
scrapy
(pip)
Sep 2, 2026
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
High
CVE-2026-62676
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
High
CVE-2026-62677
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
High
CVE-2026-62388
was published
for
nltk
(pip)
Sep 2, 2026
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
High
CVE-2026-76098
was published
for
mistune
(pip)
Sep 2, 2026
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
High
CVE-2026-82397
was published
for
tornado
(pip)
Sep 2, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
High
CVE-2026-81726
was published
for
nltk
(pip)
Sep 2, 2026
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
High
GHSA-gqvg-gmmx-x4hm
was published
for
mlflow
(pip)
Sep 1, 2026
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
High
GHSA-vf76-f5cp-9846
was published
for
nltk
(pip)
Aug 31, 2026
•
withdrawn
RestrictedPython guard hooks can be shadowed via positional-only arguments
High
CVE-2026-55830
was published
for
RestrictedPython
(pip)
Aug 28, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
High
CVE-2026-55228
was published
for
Weblate
(pip)
Aug 28, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
WsgiDAV MySQL provider has a blind SQL injection
High
CVE-2026-55509
was published
for
WsgiDAV
(pip)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots
High
GHSA-hqj7-phwp-c3fp
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y'
High
GHSA-8x48-8g7j-rqxp
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
High
GHSA-w5q8-6jpp-4246
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass
High
GHSA-rcw8-9qrw-27m2
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
eml_parser vulnerable to DoS via deeply nested parens in Received headers
High
CVE-2026-55620
was published
for
eml_parser
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API