GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
5,167 advisories
Filter by severity
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
High
CVE-2026-45725
was published
for
compliance-trestle
(pip)
May 27, 2026
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
Moderate
CVE-2026-45309
was published
for
asyncssh
(pip)
May 27, 2026
Langroid has Prompt to SQL Injection, Leading to RCE
Critical
CVE-2026-25879
was published
for
langroid
(pip)
May 27, 2026
Weblate has a Server-Side Request Forgery issue
Moderate
CVE-2025-66407
was published
for
Weblate
(pip)
May 26, 2026
instagrapi: Unsafe signup challenge path handling in instagrapi
Moderate
GHSA-ggxf-37hm-9wqf
was published
for
instagrapi
(pip)
May 23, 2026
aiograpi: Unsafe signup challenge path handling
Moderate
CVE-2026-47157
was published
for
aiograpi
(pip)
May 23, 2026
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
Moderate
CVE-2026-46715
was published
for
Flask-Security-Too
(pip)
May 22, 2026
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
High
GHSA-7m8f-hgjq-8gc9
was published
for
aiosend
(pip)
May 22, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Moderate
CVE-2026-46678
was published
for
pydantic-ai
(pip)
May 21, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
Moderate
CVE-2026-46645
was published
for
sqladmin
(pip)
May 21, 2026
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
Moderate
CVE-2026-46556
was published
for
flaskbb
(pip)
May 21, 2026
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
Moderate
CVE-2026-46561
was published
for
pyload-ng
(pip)
May 21, 2026
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
High
CVE-2026-46517
was published
for
lmdeploy
(pip)
May 21, 2026
Crawlee for Python: SSRF via sitemap-derived URLs
Low
CVE-2026-46497
was published
for
crawlee
(pip)
May 21, 2026
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
Moderate
CVE-2026-8597
was published
for
sagemaker
(pip)
May 21, 2026
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
High
CVE-2026-8596
was published
for
sagemaker
(pip)
May 21, 2026
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
High
CVE-2026-46432
was published
for
lmdeploy
(pip)
May 21, 2026
Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
Moderate
CVE-2026-46486
was published
for
mvt
(pip)
May 21, 2026
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
High
GHSA-vrxg-gm77-7q5g
was published
for
windows-mcp
(pip)
May 21, 2026
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None
High
GHSA-mw8f-w6p8-xrf4
was published
for
wger
(pip)
May 20, 2026
Diffusers: TOCTOU Trust Remote Code Bypass
High
CVE-2026-45804
was published
for
diffusers
(pip)
May 20, 2026
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
High
CVE-2026-46374
was published
for
sqlfluff
(pip)
May 19, 2026
SQLFluff: Recursive Stack Overflow in Parser
High
CVE-2026-46373
was published
for
sqlfluff
(pip)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API