Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

551 advisories

Loading
Strawberry legacy graphql-ws retains naturally completed subscription slots Low
CVE-2026-107727 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco
mauriceng98 Credited to mauriceng98 and sean-kim05 sean-kim05 sean-kim05
Docling: Configured HTTP headers sent to every remote image host named by a document Low
CVE-2026-105742 was published for docling (pip) Oct 7, 2026
wittjeff Credited to wittjeff
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
wlc may disclose API tokens to project-configured URLs Low
CVE-2026-62364 was published for wlc (pip) Sep 22, 2026
nijel Credited to nijel, type5afe, and visionxstack type5afe type5afe
visionxstack visionxstack
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure Low
CVE-2026-71514 was published for nltk (pip) Aug 22, 2026
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
MobSF has SSRF port restriction bypass in assetlinks_check Low
CVE-2026-68927 was published for mobsf (pip) Aug 18, 2026
DavidCarliez Credited to DavidCarliez
NLTK network URL validation permits SSRF to RFC 6598 shared-address-space hosts Low
CVE-2026-12372 was published for nltk (pip) Aug 10, 2026
GabrielGomesAL Credited to GabrielGomesAL and Classic298 Classic298 Classic298
thegr1ffyn Credited to thegr1ffyn
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
Classic298 Credited to Classic298
sfwani Credited to sfwani and Classic298 Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
MinicoAI Credited to MinicoAI
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks Low
CVE-2026-59821 was published for litellm (pip) Jul 22, 2026
yaaras Credited to yaaras
LiteLLM: Local file read via request-supplied OIDC file references Low
CVE-2026-59819 was published for litellm (pip) Jul 22, 2026
Wasmtime: Memory leak in C API with `externref` and `anyref` types Low
CVE-2025-61670 was published for wasmtime-bin (pip) Jul 14, 2026
alexcrichton Credited to alexcrichton
Keras: tar extraction permits symlink-based path traversal Low
CVE-2026-12482 was published for keras (pip) Jul 14, 2026
ProTip! Advisories are also available from the GraphQL API