GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,128 advisories
Filter by severity
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
High
CVE-2026-84366
was published
for
scrapy
(pip)
Sep 2, 2026
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
High
CVE-2026-62676
was published
for
omnigent
(pip)
Sep 2, 2026
fief-server Server-Side Template Injection vulnerability
Critical
GHSA-hj8m-9fhf-v7jp
was published
for
fief-server
(pip)
Jun 23, 2023
Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
High
GHSA-cpmr-mw4j-99r7
was published
for
label-studio
(pip)
Mar 24, 2023
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
High
CVE-2026-62677
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Critical
CVE-2026-62674
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
Withdrawn Advisory: Open WebUI has SSRF in /openai/models
High
CVE-2024-7959
was published
for
open-webui
(pip)
Mar 20, 2025
•
withdrawn
Withdrawn Advisory: Open WebUI Allows Admin Deletion via API Endpoint
High
CVE-2024-7039
was published
for
open-webui
(pip)
Mar 20, 2025
•
withdrawn
Withdrawn Advisory: Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
Moderate
CVE-2024-7034
was published
for
open-webui
(pip)
Mar 20, 2025
•
withdrawn
Withdrawn Advisory: Open WebUI Access Control
Moderate
CVE-2024-7040
was published
for
open-webui
(pip)
Mar 20, 2025
•
withdrawn
Withdrawn Advisory: Open WebUI JWT Key Handler
Low
CVE-2025-15603
was published
for
open-webui
(pip)
Mar 9, 2026
•
withdrawn
Withdrawn Advisory: Open WebUI/ZDI-CAN-28259
Moderate
CVE-2026-0767
was published
for
open-webui
(pip)
Jan 23, 2026
•
withdrawn
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
High
CVE-2026-62388
was published
for
nltk
(pip)
Sep 2, 2026
Duplicate Advisory: [CWE-1188] Default ENFORCE=False Disables All pathsec Security Controls
High
GHSA-8vh5-mgjj-w6hg
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Moderate
CVE-2026-63311
was published
for
nltk
(pip)
Sep 2, 2026
Duplicate Advisory: nltk: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
Moderate
GHSA-qg9p-xrhj-435m
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
Moderate
CVE-2026-66393
was published
for
nltk
(pip)
Mar 18, 2026
OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere
High
CVE-2026-43003
was published
for
ironic-python-agent
(pip)
May 1, 2026
Duplicate Advisory: Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
High
GHSA-cv2g-m8rr-888c
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
Low
CVE-2026-71514
was published
for
nltk
(pip)
Aug 22, 2026
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
Critical
CVE-2026-53710
was published
for
mcp-contextforge-gateway
(pip)
Aug 24, 2026
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
High
CVE-2026-71513
was published
for
nltk
(pip)
Aug 22, 2026
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
High
CVE-2026-72818
was published
for
nltk
(pip)
Aug 21, 2026
ProTip!
Advisories are also available from the
GraphQL API