GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
36,288 advisories
Filter by severity
pypdf: Possible large memory usage when retrieving alphabetical page labels
High
CVE-2026-103000
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
High
CVE-2026-102997
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage when parsing font data
High
CVE-2026-102996
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
High
CVE-2026-102995
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
High
CVE-2026-102994
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage when retrieving Roman page labels
High
CVE-2026-102993
was published
for
pypdf
(pip)
Oct 1, 2026
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
Critical
CVE-2026-102992
was published
for
piscina
(npm)
Oct 1, 2026
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
High
CVE-2026-102990
was published
for
basic-ftp
(npm)
Oct 1, 2026
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Moderate
CVE-2026-72788
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
Critical
CVE-2026-69085
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Oct 1, 2026
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
High
CVE-2026-102930
was published
for
virtualenv
(pip)
Sep 30, 2026
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
Moderate
CVE-2026-102938
was published
for
virtualenv
(pip)
Sep 30, 2026
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Moderate
CVE-2026-92081
was published
for
fastify
(npm)
Sep 30, 2026
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
Moderate
CVE-2026-103001
was published
for
PyJWT
(pip)
Sep 30, 2026
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
Moderate
GHSA-3hv7-mjh2-fv65
was published
for
tornado
(pip)
Sep 30, 2026
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
High
GHSA-chx6-46f5-w4vp
was published
for
tornado
(pip)
Sep 30, 2026
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
High
GHSA-c2m8-h5v5-343r
was published
for
tornado
(pip)
Sep 30, 2026
GitPython submodule update path traversal can write outside the repository
Moderate
GHSA-59cr-6r3x-644w
was published
for
GitPython
(pip)
Sep 30, 2026
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
Moderate
CVE-2026-93981
was published
for
hono
(npm)
Sep 30, 2026
fastify vulnerable to request body replacement via an async validation result collision
High
CVE-2026-84504
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
High
CVE-2026-76169
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
High
CVE-2026-84469
was published
for
fastify
(npm)
Sep 30, 2026
fastify vulnerable to header validation bypass via incomplete schema case normalization
High
CVE-2026-84428
was published
for
fastify
(npm)
Sep 30, 2026
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
Moderate
CVE-2026-102820
was published
for
pageant
(Rust)
Sep 30, 2026
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
Moderate
CVE-2026-102821
was published
for
russh
(Rust)
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API