Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,288 advisories

Loading
pypdf: Possible large memory usage when retrieving alphabetical page labels High
CVE-2026-103000 was published for pypdf (pip) Oct 1, 2026
manop55555 Credited to manop55555 and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up) High
CVE-2026-102997 was published for pypdf (pip) Oct 1, 2026
geoffrey-diederichs Credited to geoffrey-diederichs and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible large memory usage when parsing font data High
CVE-2026-102996 was published for pypdf (pip) Oct 1, 2026
jungmingi-lab Credited to jungmingi-lab and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) High
CVE-2026-102995 was published for pypdf (pip) Oct 1, 2026
jungmingi-lab Credited to jungmingi-lab and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes/large memory usage when parsing indirect objects High
CVE-2026-102994 was published for pypdf (pip) Oct 1, 2026
jankesec Credited to jankesec and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible large memory usage when retrieving Roman page labels High
CVE-2026-102993 was published for pypdf (pip) Oct 1, 2026
Nivid42 Credited to Nivid42 and stefan6419846 stefan6419846 stefan6419846
Fcmam5 Credited to Fcmam5
NotAFlightRisk Credited to NotAFlightRisk
SiYuan discloses an administrator's open documents and search terms to anonymous readers Moderate
CVE-2026-72788 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking Critical
CVE-2026-69085 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use High
CVE-2026-102930 was published for virtualenv (pip) Sep 30, 2026
gaborbernat Credited to gaborbernat
gaborbernat Credited to gaborbernat
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses Moderate
CVE-2026-92081 was published for fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
tritsystem Credited to tritsystem
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS Moderate
GHSA-3hv7-mjh2-fv65 was published for tornado (pip) Sep 30, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and manus-pi manus-pi manus-pi
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and aoto-tech aoto-tech aoto-tech
Tornado: StaticFileHandler follows symlinks outside static root (path traversal) High
GHSA-c2m8-h5v5-343r was published for tornado (pip) Sep 30, 2026
Yasha-ops Credited to Yasha-ops and iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
GitPython submodule update path traversal can write outside the repository Moderate
GHSA-59cr-6r3x-644w was published for GitPython (pip) Sep 30, 2026
kta1kri Credited to kta1kri
hono/jsx renders plain strings unescaped in boundary components, leading to XSS Moderate
CVE-2026-93981 was published for hono (npm) Sep 30, 2026
ggmolly Credited to ggmolly
fastify vulnerable to request body replacement via an async validation result collision High
CVE-2026-84504 was published for fastify (npm) Sep 30, 2026
velgusgus599 Credited to velgusgus599, UlisesGascon, climba03003, and mcollina UlisesGascon UlisesGascon
climba03003 climba03003 mcollina mcollina
vvvvvvvvvvitel Credited to vvvvvvvvvvitel, mcollina, UlisesGascon, schecthellraiser606, and B1gN0Se mcollina mcollina
UlisesGascon UlisesGascon schecthellraiser606 schecthellraiser606 B1gN0Se B1gN0Se
fastify vulnerable to request validation bypass via skipped boolean false schemas High
CVE-2026-84469 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, UlisesGascon, and climba03003 mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003
fastify vulnerable to header validation bypass via incomplete schema case normalization High
CVE-2026-84428 was published for fastify (npm) Sep 30, 2026
schecthellraiser606 Credited to schecthellraiser606, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Guigu98 Credited to Guigu98
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey Moderate
CVE-2026-102821 was published for russh (Rust) Sep 30, 2026
Guigu98 Credited to Guigu98
ProTip! Advisories are also available from the GraphQL API