GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,036 advisories
Filter by severity
Agno session state overwrites between different sessions/users
High
CVE-2025-64168
was published
for
agno
(pip)
Oct 31, 2025
Ansible does not collect garbage after playbook run
Moderate
CVE-2020-25635
was published
for
ansible
(pip)
Oct 31, 2025
cryptidy allows code execution via untrusted data due to pickle.loads
Moderate
CVE-2025-63675
was published
for
cryptidy
(pip)
Oct 31, 2025
Brotli is vulnerable to a denial of service (DoS) attack due to decompression
High
CVE-2025-6176
was published
for
brotli
(pip)
Oct 31, 2025
Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12060
was published
for
keras
(pip)
Oct 30, 2025
Byaidu PDFMathTranslate vulnerable to open redirect
Low
CVE-2025-50736
was published
for
pdf2zh
(pip)
Oct 30, 2025
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
Moderate
CVE-2025-54941
was published
for
apache-airflow
(pip)
Oct 30, 2025
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Moderate
CVE-2025-62402
was published
for
apache-airflow
(pip)
Oct 30, 2025
Apache Airflow's create action can upsert existing Pools/Connections/Variables
Moderate
CVE-2025-62503
was published
for
apache-airflow
(pip)
Oct 30, 2025
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
High
CVE-2025-64104
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 29, 2025
OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability
Moderate
GHSA-grjp-54v3-c442
was published
for
usd-core
(pip)
Oct 29, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
CKAN vulnerable to fixed session IDs
Moderate
CVE-2025-64100
was published
for
ckan
(pip)
Oct 29, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Moderate
CVE-2025-62801
was published
for
fastmcp
(pip)
Oct 29, 2025
FastMCP vulnerable to reflected XSS in client's callback page
Moderate
CVE-2025-62800
was published
for
fastmcp
(pip)
Oct 29, 2025
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
High
GHSA-c2jp-c369-7pvx
was published
for
fastmcp
(pip)
Oct 29, 2025
CKAN vulnerable to stored XSS in resource description
Moderate
CVE-2025-54384
was published
for
ckan
(pip)
Oct 29, 2025
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
Moderate
CVE-2025-12058
was published
for
keras
(pip)
Oct 29, 2025
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
High
CVE-2025-62727
was published
for
starlette
(pip)
Oct 28, 2025
BBOT's gitlab.py exposes globally configured "gitlab" API key
Moderate
CVE-2025-10282
was published
for
bbot
(pip)
Oct 27, 2025
pg8000 SQL injection vulnerability via a specially crafted Python list input
High
CVE-2025-61385
was published
for
pg8000
(pip)
Oct 27, 2025
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
High
CVE-2025-8709
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 26, 2025
pypdf can exhaust RAM via manipulated LZWDecode streams
Moderate
CVE-2025-62708
was published
for
pypdf
(pip)
Oct 22, 2025
pypdf possibly loops infinitely when reading DCT inline images without EOF marker
Moderate
CVE-2025-62707
was published
for
pypdf
(pip)
Oct 22, 2025
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
High
CVE-2025-62611
was published
for
aiomysql
(pip)
Oct 22, 2025
ProTip!
Advisories are also available from the
GraphQL API