GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,239
NuGet
754
pip
4,003
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,522 advisories
Filter by severity
Cadwyn vulnerable to XSS on the docs page
High
CVE-2025-53528
was published
for
cadwyn
(pip)
Jul 21, 2025
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
CVE-2025-6998
was published
for
calibreweb
(pip)
Jul 24, 2025
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
High
CVE-2025-54412
was published
for
skops
(pip)
Jul 25, 2025
Apache Spark UI can allow impersonation if ACLs enabled
High
CVE-2022-33891
was published
for
org.apache.spark:spark-parent_2.12
(Maven)
Jul 19, 2022
Bugsink path traversal via event_id in ingestion
High
CVE-2025-54433
was published
for
bugsink
(pip)
Jul 29, 2025
Minerva timing attack on P-256 in python-ecdsa
High
CVE-2024-23342
was published
for
ecdsa
(pip)
Jan 22, 2024
LangChain pickle deserialization of untrusted data
High
CVE-2024-5998
was published
for
langchain-community
(pip)
Sep 17, 2024
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2025-30167
was published
for
jupyter_core
(pip)
Jun 4, 2025
Withdrawn Advisory: ReDoS in py library when used with subversion
High
CVE-2022-42969
was published
for
py
(pip)
Oct 16, 2022
•
withdrawn
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
High
CVE-2025-54796
was published
for
copyparty
(pip)
Aug 4, 2025
Webargs mishandles concurrent JSON parsing
High
CVE-2019-9710
was published
for
webargs
(pip)
Mar 12, 2019
Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
High
GHSA-9gvj-pp9x-gcfr
was published
for
picklescan
(pip)
Aug 12, 2025
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
High
CVE-2025-55156
was published
for
pyload-ng
(pip)
Aug 12, 2025
Duplicate Advisory: Keras safe mode bypass vulnerability
High
GHSA-pwq7-2gvj-vg9v
was published
for
keras
(pip)
Aug 11, 2025
•
withdrawn
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
High
CVE-2025-8747
was published
for
keras
(pip)
Aug 12, 2025
OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
High
CVE-2025-48071
was published
for
OpenEXR
(pip)
Jul 31, 2025
Pillow Uncontrolled Resource Consumption
High
CVE-2021-27922
was published
for
pillow
(pip)
Mar 18, 2021
Pillow Denial of Service by Uncontrolled Resource Consumption
High
CVE-2021-27921
was published
for
Pillow
(pip)
Mar 18, 2021
Pillow Denial of Service by Uncontrolled Resource Consumption
High
CVE-2021-27923
was published
for
pillow
(pip)
Mar 18, 2021
Copier's safe template has arbitrary filesystem read/write access
High
CVE-2025-55201
was published
for
copier
(pip)
Aug 18, 2025
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
High
CVE-2025-9141
was published
for
vllm
(pip)
Aug 21, 2025
vllm API endpoints vulnerable to Denial of Service Attacks
High
CVE-2025-48956
was published
for
vllm
(pip)
Aug 21, 2025
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
High
CVE-2025-57751
was published
for
pyload-ng
(pip)
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API