GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
53 advisories
Filter by severity
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
High
CVE-2026-67445
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
High
CVE-2026-67446
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
High
CVE-2026-55523
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Critical
CVE-2026-47698
was published
for
vm2
(npm)
Aug 17, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
Moderate
CVE-2026-56818
was published
for
io.netty:netty-codec-redis
(Maven)
Aug 7, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
Low
GHSA-v3j6-27vc-7pw2
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
Low
GHSA-qh5g-q395-cx4j
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
Moderate
GHSA-56m6-8q75-f2rw
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
Moderate
CVE-2026-55597
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
Moderate
CVE-2026-55595
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
Moderate
CVE-2026-55594
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
CVE-2026-73416
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API