GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
108 advisories
Filter by severity
unstructured: Server-Side Request Forgery in the URL-based partitioning
Critical
CVE-2026-71428
was published
for
unstructured
(pip)
Sep 3, 2026
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
Moderate
CVE-2026-54770
was published
for
webob
(pip)
Aug 27, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint
Moderate
CVE-2026-54724
was published
for
kiwitcms
(pip)
Jul 6, 2026
Flask-Security has an Open Redirect issue
Moderate
GHSA-w2j7-f3c6-g8cw
was published
for
Flask-Security
(pip)
Jun 23, 2026
Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
Moderate
CVE-2026-41479
was published
for
authlib
(pip)
Jun 8, 2026
WebOb: Location header normalization during redirect leads to open redirect - again
Moderate
CVE-2026-44889
was published
for
webob
(pip)
Jun 4, 2026
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
High
CVE-2026-40961
was published
for
apache-airflow
(pip)
Jun 1, 2026
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
Moderate
CVE-2026-44681
was published
for
authlib
(pip)
May 13, 2026
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
Moderate
CVE-2026-44520
was published
for
docling-graph
(pip)
May 7, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
High
CVE-2026-44503
was published
for
Microsoft.Kiota.Abstractions
(Go)
May 7, 2026
wger: trainer_login open redirect - ?next= parameter not validated against host
Moderate
GHSA-vqv8-j3mj-wjxj
was published
for
wger
(pip)
May 6, 2026
Jupyter Server has an open redirection vulnerability in `next` query parameter
Moderate
CVE-2025-61669
was published
for
jupyter-server
(pip)
May 5, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
JupyterHub has an Open Redirect Vulnerability
Moderate
CVE-2026-33709
was published
for
jupyterhub
(pip)
Apr 3, 2026
django-allauth has an open redirect vulnerability
Moderate
CVE-2026-27982
was published
for
django-allauth
(pip)
Mar 5, 2026
IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links
High
CVE-2026-28681
was published
for
irrd
(pip)
Mar 4, 2026
Products.isurlinportal has possible open redirect when using more than 2 forward slashes
Moderate
CVE-2026-28413
was published
for
Products.isurlinportal
(pip)
Mar 2, 2026
Gradio has an Open Redirect in its OAuth Flow
Moderate
CVE-2026-28415
was published
for
gradio
(pip)
Mar 1, 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
High
CVE-2026-25732
was published
for
nicegui
(pip)
Feb 5, 2026
web2py has an Open Redirect Vulnerability
Moderate
CVE-2026-25198
was published
for
web2py
(pip)
Feb 5, 2026
WeasyPrint has a Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
High
CVE-2025-68616
was published
for
weasyprint
(pip)
Jan 20, 2026
Mayan EDMS has an Open Redirect through the /authentication/ file
Low
CVE-2025-14692
was published
for
mayan-edms
(pip)
Dec 15, 2025
Open Redirect Vulnerability in Taguette
Moderate
CVE-2025-67502
was published
for
taguette
(pip)
Dec 9, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API