GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,791
Erlang
36
GitHub Actions
29
Go
2,373
Maven
5,000+
npm
3,998
NuGet
720
pip
3,799
Pub
12
RubyGems
927
Rust
984
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,052 advisories
Filter by severity
Cosmos SDK's Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt
High
GHSA-p22h-3m2v-cmgh
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jul 8, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content
High
CVE-2025-53547
was published
for
helm.sh/helm/v3
(Go)
Jul 8, 2025
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
High
CVE-2025-7346
was published
for
pyload-ng
(pip)
Jul 8, 2025
MCP Server Kubernetes vulnerable to command injection in several tools
High
CVE-2025-53355
was published
for
mcp-server-kubernetes
(npm)
Jul 8, 2025
Babylon vulnerable to chain halt when a message modifies the validator set at the epoch boundary
High
GHSA-rj53-j6jw-7f7g
was published
for
github.com/babylonlabs-io/babylon/v2
(Go)
Jul 8, 2025
Cloudflare Vite plugin exposes secrets over the built-in dev server
Moderate
GHSA-4pfg-2mw5-f8jx
was published
for
@cloudflare/vite-plugin
(npm)
Jul 8, 2025
Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection
High
CVE-2025-53372
was published
for
node-code-sandbox-mcp
(npm)
Jul 8, 2025
Duplicate Advisory: GHSA-x698-5hjm-w2m5
High
GHSA-2wcm-vx67-3x4q
was published
for
pyload-ng
(pip)
Jul 8, 2025
•
withdrawn
fastapi-guard is vulnerable to ReDoS through inefficient regex
Moderate
CVE-2025-53539
was published
for
fastapi-guard
(pip)
Jul 7, 2025
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Low
CVE-2025-53535
was published
for
better-auth
(npm)
Jul 7, 2025
Dagster vulnerable to Path Traversal attack through its /logs endpoint
Moderate
CVE-2023-51232
was published
for
dagster
(pip)
Jul 7, 2025
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
High
CVE-2025-6209
was published
for
llama-index-core
(pip)
Jul 7, 2025
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Moderate
CVE-2025-5472
was published
for
llama-index-core
(pip)
Jul 7, 2025
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
Moderate
CVE-2025-6210
was published
for
llama-index-readers-obsidian
(pip)
Jul 7, 2025
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
High
CVE-2025-6386
was published
for
lollms
(pip)
Jul 7, 2025
LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
High
CVE-2025-3046
was published
for
llama-index-readers-obsidian
(pip)
Jul 7, 2025
LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
Moderate
CVE-2025-3044
was published
for
llama-index-readers-papers
(pip)
Jul 7, 2025
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
High
CVE-2025-3225
was published
for
llama-index-readers-papers
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Moderate
CVE-2025-3262
was published
for
transformers
(pip)
Jul 7, 2025
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
Moderate
CVE-2025-3263
was published
for
transformers
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its get_imports() function
Moderate
CVE-2025-3264
was published
for
transformers
(pip)
Jul 7, 2025
Transformers's Improper Input Validation vulnerability can be exploited through username injection
Low
CVE-2025-3777
was published
for
transformers
(pip)
Jul 7, 2025
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
Moderate
CVE-2025-3108
was published
for
llama-index-core
(pip)
Jul 7, 2025
rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
CVE-2025-53605
was published
for
protobuf
(Rust)
Jul 5, 2025
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Moderate
CVE-2025-53604
was published
for
web-push
(Rust)
Jul 5, 2025
ProTip!
Advisories are also available from the
GraphQL API