Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

108 advisories

Loading
unstructured: Server-Side Request Forgery in the URL-based partitioning Critical
CVE-2026-71428 was published for unstructured (pip) Sep 3, 2026
hayato1121 Credited to hayato1121
WebOb: Open redirect in Location header normalization via leading C0 control / space characters Moderate
CVE-2026-54770 was published for webob (pip) Aug 27, 2026
tonghuaroot Credited to tonghuaroot, digitalresistor, and polkorny digitalresistor digitalresistor
polkorny polkorny
thegr1ffyn Credited to thegr1ffyn
Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint Moderate
CVE-2026-54724 was published for kiwitcms (pip) Jul 6, 2026
martindios Credited to martindios
Flask-Security has an Open Redirect issue Moderate
GHSA-w2j7-f3c6-g8cw was published for Flask-Security (pip) Jun 23, 2026
RacerZ-fighting Credited to RacerZ-fighting and Fushuling Fushuling Fushuling
WebOb: Location header normalization during redirect leads to open redirect - again Moderate
CVE-2026-44889 was published for webob (pip) Jun 4, 2026
Apache Airflow: Authenticated users can bypass the `is_safe_url` check High
CVE-2026-40961 was published for apache-airflow (pip) Jun 1, 2026
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect Moderate
CVE-2026-44681 was published for authlib (pip) May 13, 2026
y011d4 Credited to y011d4
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler Moderate
CVE-2026-44520 was published for docling-graph (pip) May 7, 2026
ayoub-ibm Credited to ayoub-ibm and dolfim-ibm dolfim-ibm dolfim-ibm
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer, awsactran, and sgracia714 awsactran awsactran
sgracia714 sgracia714
wger: trainer_login open redirect - ?next= parameter not validated against host Moderate
GHSA-vqv8-j3mj-wjxj was published for wger (pip) May 6, 2026
whatisproblem Credited to whatisproblem
Jupyter Server has an open redirection vulnerability in `next` query parameter Moderate
CVE-2025-61669 was published for jupyter-server (pip) May 5, 2026
dlqqq Credited to dlqqq, niwasak1, Yann-P, and Carreau niwasak1 niwasak1
Yann-P Yann-P Carreau Carreau
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS High
CVE-2026-40171 was published for @jupyter-notebook/help-extension (npm) Apr 30, 2026
dtrops Credited to dtrops, Carreau, Yann-P, krassowski, and jtpio Carreau Carreau
Yann-P Yann-P krassowski krassowski jtpio jtpio
JupyterHub has an Open Redirect Vulnerability Moderate
CVE-2026-33709 was published for jupyterhub (pip) Apr 3, 2026
RacerZ-fighting Credited to RacerZ-fighting and Fushuling Fushuling Fushuling
django-allauth has an open redirect vulnerability Moderate
CVE-2026-27982 was published for django-allauth (pip) Mar 5, 2026
BrookeYangRui Credited to BrookeYangRui
Products.isurlinportal has possible open redirect when using more than 2 forward slashes Moderate
CVE-2026-28413 was published for Products.isurlinportal (pip) Mar 2, 2026
ale-rt Credited to ale-rt
Gradio has an Open Redirect in its OAuth Flow Moderate
CVE-2026-28415 was published for gradio (pip) Mar 1, 2026
logicx24 Credited to logicx24
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write High
CVE-2026-25732 was published for nicegui (pip) Feb 5, 2026
k14uz Credited to k14uz, falkoschindler, and evnchn falkoschindler falkoschindler
evnchn evnchn
web2py has an Open Redirect Vulnerability Moderate
CVE-2026-25198 was published for web2py (pip) Feb 5, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect High
CVE-2025-68616 was published for weasyprint (pip) Jan 20, 2026
g4nkd Credited to g4nkd
Mayan EDMS has an Open Redirect through the /authentication/ file Low
CVE-2025-14692 was published for mayan-edms (pip) Dec 15, 2025
Open Redirect Vulnerability in Taguette Moderate
CVE-2025-67502 was published for taguette (pip) Dec 9, 2025
yueyueL Credited to yueyueL
Open redirect endpoint in Datasette Low
CVE-2025-64481 was published for datasette (pip) Nov 6, 2025
jamesjefferies Credited to jamesjefferies
ProTip! Advisories are also available from the GraphQL API