Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,128 advisories

Loading
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default High
CVE-2026-84366 was published for scrapy (pip) Sep 2, 2026
syncrain Credited to syncrain
aaronjmars Credited to aaronjmars
fief-server Server-Side Template Injection vulnerability Critical
GHSA-hj8m-9fhf-v7jp was published for fief-server (pip) Jun 23, 2023
rotil Credited to rotil and yhay81 yhay81 yhay81
Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/ High
GHSA-cpmr-mw4j-99r7 was published for label-studio (pip) Mar 24, 2023
c3l3si4n Credited to c3l3si4n, farioas, and yhay81 farioas farioas
yhay81 yhay81
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE Critical
CVE-2026-62674 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools High
CVE-2026-62675 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Withdrawn Advisory: Open WebUI has SSRF in /openai/models High
CVE-2024-7959 was published for open-webui (pip) Mar 20, 2025 withdrawn
Classic298 Credited to Classic298
Withdrawn Advisory: Open WebUI Allows Admin Deletion via API Endpoint High
CVE-2024-7039 was published for open-webui (pip) Mar 20, 2025 withdrawn
Classic298 Credited to Classic298
Withdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint Moderate
CVE-2024-7034 was published for open-webui (pip) Mar 20, 2025 withdrawn
Classic298 Credited to Classic298
Withdrawn Advisory: Open WebUI Access Control Moderate
CVE-2024-7040 was published for open-webui (pip) Mar 20, 2025 withdrawn
Classic298 Credited to Classic298
Withdrawn Advisory: Open WebUI JWT Key Handler Low
CVE-2025-15603 was published for open-webui (pip) Mar 9, 2026 withdrawn
Classic298 Credited to Classic298
Withdrawn Advisory: Open WebUI/ZDI-CAN-28259 Moderate
CVE-2026-0767 was published for open-webui (pip) Jan 23, 2026 withdrawn
Classic298 Credited to Classic298
NLTK: Default ENFORCE=False Disables All pathsec Security Controls High
CVE-2026-62388 was published for nltk (pip) Sep 2, 2026
Duplicate Advisory: [CWE-1188] Default ENFORCE=False Disables All pathsec Security Controls High
GHSA-8vh5-mgjj-w6hg was published for nltk (pip) Aug 22, 2026 withdrawn
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure Moderate
CVE-2026-63311 was published for nltk (pip) Sep 2, 2026
ekaf Credited to ekaf
Duplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure Moderate
GHSA-qg9p-xrhj-435m was published for nltk (pip) Aug 22, 2026 withdrawn
pierreolivierbonin Credited to pierreolivierbonin and jperezdealgaba jperezdealgaba jperezdealgaba
ZeroXJacks Credited to ZeroXJacks and SebTardif SebTardif SebTardif
OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere High
CVE-2026-43003 was published for ironic-python-agent (pip) May 1, 2026
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure Low
CVE-2026-71514 was published for nltk (pip) Aug 22, 2026
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server Critical
CVE-2026-53710 was published for mcp-contextforge-gateway (pip) Aug 24, 2026
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution High
CVE-2026-71513 was published for nltk (pip) Aug 22, 2026
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking High
CVE-2026-72818 was published for nltk (pip) Aug 21, 2026
ProTip! Advisories are also available from the GraphQL API