Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,406 advisories

Loading
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default High
CVE-2026-84366 was published for scrapy (pip) Sep 2, 2026
syncrain Credited to syncrain
aaronjmars Credited to aaronjmars
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools High
CVE-2026-62675 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
NLTK: Default ENFORCE=False Disables All pathsec Security Controls High
CVE-2026-62388 was published for nltk (pip) Sep 2, 2026
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown High
CVE-2026-76098 was published for mistune (pip) Sep 2, 2026
wan1yan Credited to wan1yan
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop High
CVE-2026-82397 was published for tornado (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
CVE-2026-81726 was published for nltk (pip) Sep 2, 2026
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
prasanna8585 Credited to prasanna8585
Duplicate Advisory: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions High
GHSA-vf76-f5cp-9846 was published for nltk (pip) Aug 31, 2026 withdrawn
RestrictedPython guard hooks can be shadowed via positional-only arguments High
CVE-2026-55830 was published for RestrictedPython (pip) Aug 28, 2026
Neroli-realy Credited to Neroli-realy, dataflake, and taisehub dataflake dataflake
taisehub taisehub
H3xV0rT3x Credited to H3xV0rT3x, nijel, and EndlssNightmare nijel nijel
EndlssNightmare EndlssNightmare
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching High
CVE-2026-55520 was published for Protego (pip) Aug 28, 2026
black-shadow-007 Credited to black-shadow-007
WsgiDAV MySQL provider has a blind SQL injection High
CVE-2026-55509 was published for WsgiDAV (pip) Aug 28, 2026
Jvr2022 Credited to Jvr2022
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
GHSA-hqj7-phwp-c3fp was published for nltk (pip) Aug 27, 2026 withdrawn
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y' High
GHSA-8x48-8g7j-rqxp was published for nltk (pip) Aug 27, 2026 withdrawn
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
dokterbob Credited to dokterbob, qvipin, and ladderlogix qvipin qvipin
ladderlogix ladderlogix
Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement High
GHSA-w5q8-6jpp-4246 was published for nltk (pip) Aug 25, 2026 withdrawn
Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass High
GHSA-rcw8-9qrw-27m2 was published for nltk (pip) Aug 25, 2026 withdrawn
eml_parser vulnerable to DoS via deeply nested parens in Received headers High
CVE-2026-55620 was published for eml_parser (pip) Aug 25, 2026
Sebasteuo Credited to Sebasteuo
ProTip! Advisories are also available from the GraphQL API