GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,471
Erlang
33
GitHub Actions
24
Go
2,181
Maven
5,000+
npm
3,837
NuGet
696
pip
3,556
Pub
12
RubyGems
910
Rust
910
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,760 advisories
Filter by severity
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
CVE-2025-30160
was published
for
redlib
(Rust)
Mar 21, 2025
Envoy crashes when HTTP ext_proc processes local replies
Moderate
CVE-2025-30157
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 21, 2025
Authorization Bypass in Next.js Middleware
Critical
CVE-2025-29927
was published
for
next
(npm)
Mar 21, 2025
Libcontainer is affected by capabilities elevation similar to GHSA-f3fp-gc8g-vw66
Moderate
CVE-2025-27612
was published
for
libcontainer
(Rust)
Mar 21, 2025
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Low
CVE-2025-29923
was published
for
github.com/redis/go-redis/v9
(Go)
Mar 20, 2025
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace
Critical
CVE-2025-29922
was published
for
github.com/kcp-dev/kcp
(Go)
Mar 20, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Moderate
CVE-2025-29914
was published
for
github.com/corazawaf/coraza/v3
(Go)
Mar 20, 2025
LiteLLM Has an Improper Authorization Vulnerability
High
CVE-2025-0628
was published
for
litellm
(pip)
Mar 20, 2025
LiteLLM Has a Leakage of Langfuse API Keys
High
CVE-2025-0330
was published
for
litellm
(pip)
Mar 20, 2025
LiteLLM Reveals Portion of API Key via a Logging File
High
CVE-2024-9606
was published
for
litellm
(pip)
Mar 20, 2025
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
High
CVE-2024-9840
was published
for
open-webui
(npm)
Mar 20, 2025
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
Moderate
CVE-2024-9900
was published
for
github.com/mudler/LocalAI
(Go)
Mar 20, 2025
Kedro deserialization vulnerability
Critical
CVE-2024-9701
was published
for
kedro
(pip)
Mar 20, 2025
ZenML unauthenticated DoS via Multipart Boundry
High
CVE-2024-9340
was published
for
zenml
(pip)
Mar 20, 2025
Quivr unauthenticated Denial of Service (DoS) via Multipart Boundary
High
CVE-2024-9229
was published
for
quivr-core
(pip)
Mar 20, 2025
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
Critical
CVE-2024-9053
was published
for
vllm
(pip)
Mar 20, 2025
BentoML Denial of Service (DoS) via Multipart Boundary
High
CVE-2024-9056
was published
for
bentoml
(pip)
Mar 20, 2025
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
Critical
CVE-2024-9052
was published
for
vllm
(pip)
Mar 20, 2025
BentoML deserialization vulnerability
Critical
CVE-2024-9070
was published
for
bentoml
(pip)
Mar 20, 2025
composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL
Moderate
CVE-2024-8955
was published
for
composio-core
(pip)
Mar 20, 2025
LiteLLM Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
High
CVE-2024-8984
was published
for
litellm
(pip)
Mar 20, 2025
MLflow has a Local File Read/Path Traversal in dbfs
High
CVE-2024-8859
was published
for
mlflow
(pip)
Mar 20, 2025
composio Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-8952
was published
for
composio-core
(pip)
Mar 20, 2025
Gradio DOS in multipart boundry while uploading the file
High
CVE-2024-8966
was published
for
gradio
(pip)
Mar 20, 2025
AgentScope Deserialization Vulnerability
Critical
CVE-2024-8502
was published
for
agentscope
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API