GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
6,395 advisories
Filter by severity
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
High
GHSA-8mcx-5rqc-vhmf
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
Moderate
GHSA-35mr-4567-66vg
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
High
GHSA-8w8g-wq8h-fq33
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
High
GHSA-5fqc-mrg8-w798
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
High
GHSA-cm62-gvxx-vmxx
was published
for
dulwich
(pip)
Oct 2, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
Moderate
CVE-2026-102830
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
High
CVE-2026-102831
was published
for
jupyterlab
(pip)
Oct 1, 2026
virtualenv bash and fish activation scripts execute commands embedded in paths
High
CVE-2026-102925
was published
for
virtualenv
(pip)
Oct 1, 2026
virtualenv: Command injection via --prompt in activate.bat (batch activator)
High
CVE-2026-102937
was published
for
virtualenv
(pip)
Oct 1, 2026
pypdf: Possible long runtimes with large amount of embedded files
High
CVE-2026-102999
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes when generating appearance streams
High
CVE-2026-102998
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage when retrieving alphabetical page labels
High
CVE-2026-103000
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
High
CVE-2026-102997
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage when parsing font data
High
CVE-2026-102996
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
High
CVE-2026-102995
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
High
CVE-2026-102994
was published
for
pypdf
(pip)
Oct 1, 2026
pypdf: Possible large memory usage when retrieving Roman page labels
High
CVE-2026-102993
was published
for
pypdf
(pip)
Oct 1, 2026
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
High
CVE-2026-102930
was published
for
virtualenv
(pip)
Sep 30, 2026
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
Moderate
CVE-2026-102938
was published
for
virtualenv
(pip)
Sep 30, 2026
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
Moderate
CVE-2026-103001
was published
for
PyJWT
(pip)
Sep 30, 2026
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
Moderate
GHSA-3hv7-mjh2-fv65
was published
for
tornado
(pip)
Sep 30, 2026
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
High
GHSA-chx6-46f5-w4vp
was published
for
tornado
(pip)
Sep 30, 2026
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
High
GHSA-c2m8-h5v5-343r
was published
for
tornado
(pip)
Sep 30, 2026
GitPython submodule update path traversal can write outside the repository
Moderate
GHSA-59cr-6r3x-644w
was published
for
GitPython
(pip)
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API