GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,410
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,502
Swift
61
Unreviewed advisories
All unreviewed
5,000+
33,787 advisories
Filter by severity
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Moderate
CVE-2026-59222
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Low
CVE-2026-59215
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Low
CVE-2026-59213
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Moderate
CVE-2026-59217
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
High
CVE-2026-59714
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
High
CVE-2026-59219
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Low
CVE-2026-59715
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Moderate
CVE-2026-59227
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Moderate
CVE-2026-59220
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Account enumeration via observable login timing discrepancy
Moderate
CVE-2026-59218
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Stored web worker XSS via Pyodide
High
CVE-2026-59214
was published
for
open-webui
(pip)
Jul 24, 2026
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
High
CVE-2026-55607
was published
for
@anthropic-ai/claude-code
(npm)
Jul 24, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
High
GHSA-v74w-7mr3-4qg3
was published
for
io.netty:netty-codec-xml
(Maven)
Jul 24, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Moderate
GHSA-mfg7-5gfp-c4w3
was published
for
io.netty:netty-codec-dns
(Maven)
Jul 24, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
Moderate
GHSA-gcjh-h69q-9w9g
was published
for
github.com/google/cel-go
(Go)
Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service
High
GHSA-pm4m-ph32-ghv5
was published
for
js-yaml
(npm)
Jul 24, 2026
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Moderate
GHSA-g9hv-x236-4qp3
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Moderate
GHSA-cqjc-rmpq-xprq
was published
for
russh
(Rust)
Jul 24, 2026
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Moderate
GHSA-5xvq-cp9x-6p6r
was published
for
russh
(Rust)
Jul 24, 2026
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
High
GHSA-qwww-vcr4-c8h2
was published
for
react-router
(npm)
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Moderate
CVE-2026-7120
was published
for
@fastify/static
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API