Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

437 advisories

Loading
Crawlee for Python: SSRF via sitemap-derived URLs Low
CVE-2026-46497 was published for crawlee (pip) May 21, 2026
FORIMOC Credited to FORIMOC and Arturo0x90 Arturo0x90 Arturo0x90
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs Low
CVE-2026-45739 was published for strawberry-graphql (pip) May 19, 2026
lpschroer Credited to lpschroer, bellini666, and patrick91 bellini666 bellini666
patrick91 patrick91
qi-scape Credited to qi-scape and Classic298 Classic298 Classic298
justhtml introduces denial-of-service hardening Low
GHSA-r8cj-3554-33mr was published for justhtml (pip) May 8, 2026
EmilStenstrom Credited to EmilStenstrom
OSGeo GDAL vulnerable to heap-based buffer overflow Low
CVE-2026-8087 was published for GDAL (pip) May 7, 2026
OSGeo GDAL vulnerable to out-of-bounds read Low
CVE-2026-8088 was published for GDAL (pip) May 7, 2026
aiograpi has dependency on vulnerable orjson 3.11.4 (CVE-2025-67221) Low
GHSA-7mw3-79jq-xc7f was published for aiograpi (pip) May 6, 2026
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed Low
CVE-2026-42448 was published for magic-wormhole (pip) May 6, 2026
Paramiko rsakey.py allows the SHA-1 algorithm Low
CVE-2026-44405 was published for paramiko (pip) May 6, 2026
ciguard: Web UI is missing HTTP defence-in-depth headers Low
GHSA-7ww3-xvf5-cxwm was published for ciguard (pip) May 5, 2026
ciguard: discover_pipeline_files follows symlinks out of scan root Low
CVE-2026-44220 was published for ciguard (pip) May 5, 2026
ciguard: Container image runs as root (no USER directive) Low
CVE-2026-44218 was published for ciguard (pip) May 5, 2026
Microdot has HTTP response splitting in Response.set_cookie() Low
CVE-2026-42874 was published for microdot (pip) May 5, 2026
luantq0 Credited to luantq0
Langchain-Chatchat Uses Insufficiently Random Values Low
CVE-2026-7847 was published for langchain-chatchat (pip) May 5, 2026
Django Uses Cache Containing Sensitive Information Low
CVE-2026-6907 was published for Django (pip) May 5, 2026
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API Low
CVE-2026-7846 was published for langchain-chatchat (pip) May 5, 2026
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm Low
CVE-2026-7845 was published for langchain-chatchat (pip) May 5, 2026
Django Uses Persistent Cookies Containing Sensitive Information Low
CVE-2026-35192 was published for Django (pip) May 5, 2026
mem0ai mem0 has an Improper Input Validation Issue Low
CVE-2026-7597 was published for mem0ai (pip) May 2, 2026
django-mdeditor is Missing Authentication for Critical Function Low
CVE-2025-13030 was published for django-mdeditor (pip) Apr 30, 2026
auto-favicon has a Server-Side Request Forgery issue Low
CVE-2026-7150 was published for auto-favicon (pip) Apr 27, 2026
Wooey has an Incorrect Privilege Assignment issue Low
CVE-2026-7142 was published for wooey (pip) Apr 27, 2026
vLLM makes Use of Uninitialized Resource Low
CVE-2026-7141 was published for vllm (pip) Apr 27, 2026
ProTip! Advisories are also available from the GraphQL API