GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
33 advisories
Filter by severity
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
High
CVE-2026-55149
was published
for
github.com/vouch/vouch-proxy
(Go)
Aug 20, 2026
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
High
CVE-2026-59893
was published
for
sqlparse
(pip)
Aug 17, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
High
CVE-2026-73561
was published
for
@anephenix/hub
(npm)
Jul 24, 2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Moderate
CVE-2026-54249
was published
for
pydantic-ai
(pip)
Aug 13, 2026
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
High
CVE-2026-55071
was published
for
stata-mcp
(pip)
Aug 12, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
High
GHSA-p7w7-4929-vpj5
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
High
CVE-2026-59892
was published
for
@opentelemetry/propagator-jaeger
(npm)
Jul 21, 2026
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
Critical
CVE-2026-57496
was published
for
netlicensing-mcp
(pip)
Jun 18, 2026
Pi Agent: Pi loads project-local extensions without approval
Moderate
CVE-2026-54325
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
High
CVE-2026-54547
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch
High
CVE-2026-54549
was published
for
meta-ads-mcp
(pip)
Jul 17, 2026
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
High
CVE-2026-54447
was published
for
garminconnect
(pip)
Jul 15, 2026
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
High
CVE-2026-54446
was published
for
netlicensing-mcp
(pip)
Jul 14, 2026
yutu: Arbitrary File Write via MCP `caption-download` Tool
High
CVE-2026-50158
was published
for
github.com/eat-pray-ai/yutu
(Go)
Jul 14, 2026
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion
High
CVE-2026-50125
was published
for
github.com/StacklokLabs/mkp
(Go)
Jul 14, 2026
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
High
CVE-2026-54071
was published
for
BabelDOC
(pip)
Jul 10, 2026
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
High
CVE-2026-54063
was published
for
github.com/xuri/excelize/v2
(Go)
Jul 10, 2026
VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
High
GHSA-rpj2-4hq8-938g
was published
for
vcrpy
(pip)
Jun 19, 2026
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
High
CVE-2026-55786
was published
for
flyto-core
(pip)
Jul 6, 2026
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
Critical
CVE-2026-50027
was published
for
mcp-memory-service
(pip)
Jul 2, 2026
Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token
High
CVE-2026-50143
was published
for
@apify/actors-mcp-server
(npm)
Jul 1, 2026
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
High
CVE-2026-49986
was published
for
neuro-cortex-memory
(pip)
Jul 1, 2026
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
High
CVE-2026-49857
was published
for
auth-fetch-mcp
(npm)
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API