GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
67 advisories
Filter by severity
Copyparty vulnerable to file/dirkey confusion
Moderate
CVE-2026-70657
was published
for
copyparty
(pip)
Aug 18, 2026
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
Moderate
CVE-2026-71433
was published
for
langgraph-checkpoint-postgres
(pip)
Aug 6, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Moderate
CVE-2026-70488
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Moderate
CVE-2026-70484
was published
for
open-webui
(pip)
Aug 4, 2026
OnionShare Receive mode writes uploaded files even when file uploads are disabled
Moderate
CVE-2026-54707
was published
for
onionshare-cli
(pip)
Jul 31, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Moderate
CVE-2026-59217
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Moderate
CVE-2026-59227
was published
for
open-webui
(pip)
Jul 24, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Moderate
GHSA-f66q-9rf6-8795
was published
for
Flask-Security-Too
(pip)
Jul 7, 2026
Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
Moderate
CVE-2026-55163
was published
for
lemur
(pip)
Jun 25, 2026
LangGraph SDK has unsafe URL path construction
Moderate
CVE-2026-48776
was published
for
langgraph-sdk
(pip)
Jun 25, 2026
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
Moderate
GHSA-x44p-gg67-52fc
was published
for
praisonai
(pip)
Jun 19, 2026
•
withdrawn
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Moderate
CVE-2026-54022
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Moderate
CVE-2026-54021
was published
for
open-webui
(pip)
Jun 17, 2026
OpenStack Neutron has an Incorrect Authorization issue
Moderate
CVE-2026-49299
was published
for
neutron
(pip)
May 29, 2026
OpenStack Keystone has an Incorrect Authorization issue
Moderate
CVE-2026-43000
was published
for
keystone
(pip)
May 28, 2026
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
Moderate
CVE-2026-44394
was published
for
keystone
(pip)
May 28, 2026
OpenStack Keystone has an Authorization Bypass
Moderate
CVE-2026-42999
was published
for
keystone
(pip)
May 28, 2026
OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential
Moderate
CVE-2026-42998
was published
for
keystone
(pip)
May 28, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
Moderate
CVE-2026-42526
was published
for
apache-airflow-providers-amazon
(pip)
May 19, 2026
Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
Moderate
CVE-2026-45339
was published
for
open-webu
(pip)
May 14, 2026
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
Moderate
CVE-2026-44681
was published
for
authlib
(pip)
May 13, 2026
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
Moderate
CVE-2026-44561
was published
for
open-webui
(pip)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API