Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,401 advisories

Loading
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode Moderate
CVE-2026-105750 was published for docling (pip) Oct 6, 2026
priyankn Credited to priyankn and DavidCarliez DavidCarliez DavidCarliez
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
Werkzeug safe_join() allows Windows special device names Moderate
CVE-2026-102598 was published for Werkzeug (pip) Oct 5, 2026
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection Critical
CVE-2026-102829 was published for @simple-git/argv-parser (npm) Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration Critical
CVE-2026-102828 was published for simple-git (npm) Oct 5, 2026
sec-reex Credited to sec-reex
simple-git allows command execution through unblocked Git configuration includes High
CVE-2026-102826 was published for simple-git (npm) Oct 5, 2026
bhaswanthc Credited to bhaswanthc and NotAFlightRisk NotAFlightRisk NotAFlightRisk
anir0y Credited to anir0y, bilguunbicktivism, cruzryan, the-vibe-dev, D7EAD, dellalibera, gdegrange, b1ue0ceanRun, internetteletubbie, and arundr0id bilguunbicktivism bilguunbicktivism
cruzryan cruzryan the-vibe-dev the-vibe-dev D7EAD D7EAD dellalibera dellalibera gdegrange gdegrange b1ue0ceanRun b1ue0ceanRun internetteletubbie internetteletubbie arundr0id arundr0id
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup High
CVE-2026-102600 was published for @socket.io/cluster-engine (npm) Oct 5, 2026
manus-use Credited to manus-use
Filament: Multi-factor authentication (app) management actions do not require password reauthentication Moderate
CVE-2026-104181 was published for filament/filament (Composer) Oct 5, 2026
Yezper Credited to Yezper and danharrin danharrin danharrin
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion Moderate
CVE-2026-102275 was published for PyJWT (pip) Oct 5, 2026
ze3tar Credited to ze3tar
h-t-m Credited to h-t-m
0xiviel Credited to 0xiviel and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion Moderate
CVE-2026-105760 was published for vllm (pip) Oct 5, 2026
adithyan-ak Credited to adithyan-ak and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features Moderate
CVE-2026-105754 was published for vllm (pip) Oct 5, 2026
KernelClint Credited to KernelClint and jperezdealgaba jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
KernelClint Credited to KernelClint, dhalf, and jperezdealgaba dhalf dhalf
jperezdealgaba jperezdealgaba
uv: Path traversal on Windows through wheel extraction Moderate
CVE-2026-104843 was published for uv (pip) Oct 5, 2026
woodruffw Credited to woodruffw, charliermarsh, and White0xdi3 charliermarsh charliermarsh
White0xdi3 White0xdi3
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup Moderate
CVE-2026-102991 was published for Mako (pip) Oct 5, 2026
euriconicacio Credited to euriconicacio
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line Moderate
GHSA-r4xh-jqrq-34v2 was published for smol-toml (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
KaTeX: Existing prototype pollution can bypass trust restrictions Low
CVE-2026-103923 was published for katex (npm) Oct 5, 2026
joostgrunwald Credited to joostgrunwald, grigoriy-reshetniak, and edemaine grigoriy-reshetniak grigoriy-reshetniak
edemaine edemaine
ProTip! Advisories are also available from the GraphQL API