GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,879
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
36,401 advisories
Filter by severity
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
Moderate
CVE-2026-105750
was published
for
docling
(pip)
Oct 6, 2026
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
Moderate
CVE-2026-105753
was published
for
vllm
(pip)
Oct 6, 2026
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
Low
CVE-2026-105752
was published
for
vllm
(pip)
Oct 6, 2026
Werkzeug safe_join() allows Windows special device names
Moderate
CVE-2026-102598
was published
for
Werkzeug
(pip)
Oct 5, 2026
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
Critical
CVE-2026-102829
was published
for
@simple-git/argv-parser
(npm)
Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration
Critical
CVE-2026-102828
was published
for
simple-git
(npm)
Oct 5, 2026
simple-git allows command execution through unblocked Git configuration includes
High
CVE-2026-102826
was published
for
simple-git
(npm)
Oct 5, 2026
simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
High
CVE-2026-102827
was published
for
simple-git
(npm)
Oct 5, 2026
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
High
CVE-2026-96749
was published
for
pymongo
(pip)
Oct 5, 2026
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
High
CVE-2026-96748
was published
for
pymongo
(pip)
Oct 5, 2026
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
Moderate
CVE-2026-96747
was published
for
pymongo
(pip)
Oct 5, 2026
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
High
CVE-2026-102600
was published
for
@socket.io/cluster-engine
(npm)
Oct 5, 2026
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
Moderate
CVE-2026-104181
was published
for
filament/filament
(Composer)
Oct 5, 2026
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
Moderate
CVE-2026-102275
was published
for
PyJWT
(pip)
Oct 5, 2026
DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
Low
GHSA-6688-9rhm-gjv2
was published
for
dompurify
(npm)
Oct 5, 2026
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
Moderate
CVE-2026-105758
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
Moderate
CVE-2026-105760
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
Moderate
CVE-2026-105754
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
Moderate
CVE-2026-105757
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
Moderate
CVE-2026-105755
was published
for
vllm
(pip)
Oct 5, 2026
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
Moderate
CVE-2026-105756
was published
for
vllm
(pip)
Oct 5, 2026
uv: Path traversal on Windows through wheel extraction
Moderate
CVE-2026-104843
was published
for
uv
(pip)
Oct 5, 2026
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
Moderate
CVE-2026-102991
was published
for
Mako
(pip)
Oct 5, 2026
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
Moderate
GHSA-r4xh-jqrq-34v2
was published
for
smol-toml
(npm)
Oct 5, 2026
KaTeX: Existing prototype pollution can bypass trust restrictions
Low
CVE-2026-103923
was published
for
katex
(npm)
Oct 5, 2026
ProTip!
Advisories are also available from the
GraphQL API