GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
5,843 advisories
Filter by severity
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
High
CVE-2026-54727
was published
for
proot-distro
(pip)
Jul 29, 2026
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
High
CVE-2026-54574
was published
for
proot-distro
(pip)
Jul 29, 2026
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
Moderate
GHSA-wchh-9x6h-7f6p
was published
for
matrix-commander
(pip)
Jul 29, 2026
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Moderate
CVE-2026-50558
was published
for
penelope-shell-handler
(pip)
Jul 29, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
High
CVE-2026-54654
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
High
CVE-2026-55389
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
High
CVE-2026-54653
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
High
CVE-2026-55391
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
High
CVE-2026-54656
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
High
CVE-2026-54690
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
High
CVE-2026-55415
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
High
CVE-2026-54621
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
High
CVE-2026-54655
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
Low
CVE-2026-55403
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
High
CVE-2026-54691
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
High
CVE-2026-55390
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
High
CVE-2026-54609
was published
for
com.quietterminal:qti-neon
(Maven)
Jul 28, 2026
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
High
CVE-2026-16796
was published
for
bedrock-agentcore
(pip)
Jul 24, 2026
libp2p: yamux connection DoS via oversized data frame
High
GHSA-hmj8-5xmh-5573
was published
for
libp2p
(pip)
Jul 24, 2026
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
High
CVE-2026-16584
was published
for
awslabs.aws-api-mcp-server
(pip)
Jul 24, 2026
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
High
GHSA-47w6-gwp4-w6vc
was published
for
vantage6
(pip)
Jul 24, 2026
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
High
GHSA-94p4-4cq8-9g67
was published
for
GitPython
(pip)
Jul 24, 2026
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
High
CVE-2026-59221
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API