Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,291 advisories

Loading
legobattman Credited to legobattman and Classic298 Classic298 Classic298
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages High
CVE-2026-70492 was published for open-webui (pip) Aug 4, 2026
maxntv Credited to maxntv and Classic298 Classic298 Classic298
manus-use Credited to manus-use and Classic298 Classic298 Classic298
tonghuaroot Credited to tonghuaroot and Classic298 Classic298 Classic298
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client High
CVE-2026-70482 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
edwardav970 Credited to edwardav970 and Classic298 Classic298 Classic298
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building High
CVE-2026-69249 was published for cryptography (pip) Aug 3, 2026
sjudson Credited to sjudson and woodruffw woodruffw woodruffw
X1AOxiang Credited to X1AOxiang
agners Credited to agners and bdraco bdraco bdraco
Black: Arbitrary file writes from unsanitized user input in cache file name High
CVE-2026-32274 was published for black (pip) Mar 12, 2026
fg0x0 Credited to fg0x0 and shaked-seal shaked-seal shaked-seal
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
Open WebUI's Insecure Message Access Breaks Authorization High
CVE-2026-44569 was published for open-webui (pip) May 11, 2026
geckosecurity Credited to geckosecurity and Classic298 Classic298 Classic298
Open WebUI has inconsistent authorization controls within memories API High
CVE-2026-44570 was published for open-webui (pip) May 11, 2026
Classic298 Credited to Classic298
Docling: Unsafe URI and Path Handling in HTML Backend High
CVE-2026-47214 was published for docling (pip) Jun 3, 2026
AnistoMejin Credited to AnistoMejin and brodmart brodmart brodmart
MONAI: Unsafe functions lead to pickle deserialization rce High
GHSA-89gg-p5r5-q6r4 was published for monai (pip) Apr 7, 2026
hnking-star Credited to hnking-star and mingxin-zheng mingxin-zheng mingxin-zheng
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs High
CVE-2026-59884 was published for pyasn1 (pip) Jul 21, 2026
mikeappsec Credited to mikeappsec, HsiangNianian, and westonsteimel HsiangNianian HsiangNianian
westonsteimel westonsteimel
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` High
CVE-2026-40110 was published for jupyter-server (pip) May 5, 2026
vnykmshr Credited to vnykmshr, Yann-P, and Carreau Yann-P Yann-P
Carreau Carreau
Yann-P Credited to Yann-P, Carreau, stef41, and krassowski Carreau Carreau
stef41 stef41 krassowski krassowski
Thumbor has path traversal via post-validation URL decoding bypass in file_loader High
CVE-2026-53502 was published for thumbor (pip) Jul 31, 2026
q1uf3ng Credited to q1uf3ng and 0xHunSec 0xHunSec 0xHunSec
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS High
CVE-2026-53505 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter High
CVE-2026-53504 was published for thumbor (pip) Jul 31, 2026
geraldino2 Credited to geraldino2
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS High
CVE-2026-53503 was published for thumbor (pip) Jul 31, 2026
m01e-40x Credited to m01e-40x
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature High
CVE-2026-53501 was published for thumbor (pip) Jul 31, 2026
ProTip! Advisories are also available from the GraphQL API