GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,502 advisories
Filter by severity
Rembg allows SSRF via /api/remove
Moderate
CVE-2025-25301
was published
for
rembg
(pip)
Mar 11, 2025
Arbitrary Code Execution via Crafted Keras Config for Model Loading
High
CVE-2025-1550
was published
for
keras
(pip)
Mar 11, 2025
Azure PromptFlow remote code execution related to Jinja templates
Moderate
CVE-2025-24986
was published
for
promptflow-core
(pip)
Mar 11, 2025
Duplicate Advisory: Keras arbitrary code execution vulnerability
High
GHSA-5478-v2w6-c6q7
was published
for
keras
(pip)
Mar 11, 2025
•
withdrawn
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1945
was published
for
picklescan
(pip)
Mar 10, 2025
Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-2fh4-gpch-vqv4
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-w6mr-mj53-x258
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Django vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-26699
was published
for
Django
(pip)
Mar 6, 2025
ray vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-1979
was published
for
ray
(pip)
Mar 6, 2025
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
High
CVE-2025-25362
was published
for
spacy-llm
(pip)
Mar 5, 2025
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Moderate
CVE-2025-27516
was published
for
Jinja2
(pip)
Mar 5, 2025
dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()
High
GHSA-3x5x-fw77-g54c
was published
for
dgl
(pip)
Mar 5, 2025
Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-hw34-rqc5-h2gm
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
CVE-2025-1716
was published
for
picklescan
(pip)
Mar 3, 2025
PyTorch Model Files Can Bypass Pickle Scanners via Unexpected Pickle Extensions
Moderate
CVE-2025-1889
was published
for
picklescan
(pip)
Mar 3, 2025
CodeChecker open redirect when URL contains multiple slashes after the product name
Moderate
CVE-2025-1300
was published
for
codechecker
(pip)
Mar 3, 2025
Duplicate Advisory: Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-vr75-hjh9-7fr6
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
Flask-AppBuilder Observable Response Discrepancy
Low
CVE-2025-24023
was published
for
flask-appbuilder
(pip)
Mar 3, 2025
Spotipy's cache file, containing spotify auth token, is created with overly broad permissions
High
CVE-2025-27154
was published
for
spotipy
(pip)
Feb 28, 2025
copyparty renders unsanitized filenames as HTML when user uploads empty files
Low
CVE-2025-27145
was published
for
copyparty
(pip)
Feb 26, 2025
LTI JupyterHub Authenticator does not properly validate JWT Signature
Critical
CVE-2023-25574
was published
for
jupyterhub-ltiauthenticator
(pip)
Feb 25, 2025
ProTip!
Advisories are also available from the
GraphQL API