GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,818
Erlang
23
GitHub Actions
38
Go
2,203
Maven
2,576
npm
2,819
NuGet
487
pip
2,656
Pub
5
RubyGems
328
Rust
877
Swift
19
Unreviewed advisories
All unreviewed
5,000+
2,656 advisories
Filter by severity
justhtml has sanitization bypass in custom policies and programmatic DOM
Moderate
GHSA-vrx2-77f2-ww34
was published
for
justhtml
(pip)
Apr 22, 2026
Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
Low
CVE-2026-41140
was published
for
poetry
(pip)
Apr 22, 2026
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
High
CVE-2026-41066
was published
for
lxml
(pip)
Apr 21, 2026
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
Moderate
CVE-2026-39378
was published
for
nbconvert
(pip)
Apr 21, 2026
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
Moderate
CVE-2026-39377
was published
for
nbconvert
(pip)
Apr 21, 2026
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Moderate
CVE-2026-35588
was published
for
glances
(pip)
Apr 21, 2026
Glances has SSRF in IP Plugin via public_api leading to credential leakage
High
CVE-2026-35587
was published
for
glances
(pip)
Apr 21, 2026
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
High
CVE-2026-34839
was published
for
Glances
(pip)
Apr 21, 2026
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
High
CVE-2026-33626
was published
for
lmdeploy
(pip)
Apr 21, 2026
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
Moderate
CVE-2026-28684
was published
for
python-dotenv
(pip)
Apr 21, 2026
RAGAS has SSRF via Multi-Modal Faithfulness Collections Module
Low
CVE-2026-6587
was published
for
ragas
(pip)
Apr 20, 2026
apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
Moderate
CVE-2026-40948
was published
for
apache-airflow-providers-keycloak
(pip)
Apr 18, 2026
Apache Airflow allows code execution through crafted XCom payloads
Critical
CVE-2026-25917
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Low
CVE-2026-32690
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Moderate
CVE-2026-30912
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
High
CVE-2026-32228
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
pretalx vulnerable to stored cross-site scripting in organizer search typeahead
High
GHSA-cjcx-jfp2-f7m2
was published
for
pretalx
(pip)
Apr 18, 2026
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders
Moderate
GHSA-jm8c-9f3j-4378
was published
for
pretalx
(pip)
Apr 18, 2026
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
High
GHSA-mjw2-v2hm-wj34
was published
for
dagster
(pip)
Apr 18, 2026
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
High
GHSA-rg3h-x3jw-7jm5
was published
for
praisonai
(pip)
Apr 17, 2026
Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
Critical
GHSA-9qhq-v63v-fv3j
was published
for
praisonai
(pip)
Apr 17, 2026
Neo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures
Low
CVE-2026-35402
was published
for
mcp-neo4j-cypher
(pip)
Apr 17, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
Critical
CVE-2026-27197
was published
for
sentry
(pip)
Apr 17, 2026
langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
Low
GHSA-r7w7-9xr2-qq2r
was published
for
langchain-openai
(pip)
Apr 16, 2026
LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
Moderate
GHSA-fv5p-p927-qmxr
was published
for
langchain-text-splitters
(pip)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API