GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
4,301 advisories
Filter by severity
Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
CVE-2026-1709
was published
for
keylime
(pip)
Feb 6, 2026
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
GHSA-27jc-jmp8-qfw5
was published
for
keylime
(pip)
Feb 6, 2026
•
withdrawn
A single post-release of dydx-v4-client contained obfuscated multi-stage loader
Critical
GHSA-4f84-67cv-qrv3
was published
for
dydx-v4-client
(pip)
Feb 6, 2026
MCP-Salesforce's arbitrary attribute access leads to disclosure of Salesforce auth token
High
CVE-2026-25650
was published
for
mcp-salesforce-connector
(pip)
Feb 6, 2026
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
High
CVE-2026-25640
was published
for
pydantic-ai
(pip)
Feb 6, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
Critical
CVE-2026-25592
was published
for
Microsoft.SemanticKernel.Core
(NuGet)
Feb 6, 2026
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
High
CVE-2026-25580
was published
for
pydantic-ai
(pip)
Feb 6, 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
High
CVE-2026-25732
was published
for
nicegui
(pip)
Feb 5, 2026
pgadmin4 affected by a Restore restriction bypass via key disclosure vulnerability
High
CVE-2026-1707
was published
for
pgadmin4
(pip)
Feb 5, 2026
NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content
Moderate
CVE-2026-25516
was published
for
nicegui
(pip)
Feb 5, 2026
web2py has an Open Redirect Vulnerability
Moderate
CVE-2026-25198
was published
for
web2py
(pip)
Feb 5, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
Critical
CVE-2026-25632
was published
for
epyt-flow
(pip)
Feb 4, 2026
Wagtail has improper permission handling on admin preview endpoints
Moderate
CVE-2026-25517
was published
for
wagtail
(pip)
Feb 3, 2026
Duplicate Advisory: Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-8x2r-v9x5-3qgh
was published
for
pdfminer.six
(pip)
Feb 3, 2026
•
withdrawn
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
High
CVE-2025-70560
was published
for
boltz
(pip)
Feb 3, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Critical
CVE-2025-64712
was published
for
unstructured
(pip)
Feb 3, 2026
Django has Observable Timing Discrepancy
Low
CVE-2025-13473
was published
for
Django
(pip)
Feb 3, 2026
Django has Inefficient Algorithmic Complexity
Low
CVE-2026-1285
was published
for
Django
(pip)
Feb 3, 2026
Django has Inefficient Algorithmic Complexity
Low
CVE-2025-14550
was published
for
Django
(pip)
Feb 3, 2026
SageMaker Python SDK has Exposed HMAC
High
CVE-2026-1777
was published
for
sagemaker
(pip)
Feb 2, 2026
SageMaker Python SDK has Insecure TLS Configuration
High
CVE-2026-1778
was published
for
sagemaker
(pip)
Feb 2, 2026
Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
Critical
CVE-2026-25505
was published
for
bambuddy
(pip)
Feb 2, 2026
ProTip!
Advisories are also available from the
GraphQL API