GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,791
Erlang
36
GitHub Actions
29
Go
2,371
Maven
5,000+
npm
3,997
NuGet
720
pip
3,796
Pub
12
RubyGems
927
Rust
984
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,046 advisories
Filter by severity
Babylon vulnerable to chain halt when a message modifies the validator set at the epoch boundary
High
GHSA-rj53-j6jw-7f7g
was published
for
github.com/babylonlabs-io/babylon/v2
(Go)
Jul 8, 2025
Cloudflare Vite plugin exposes secrets over the built-in dev server
Moderate
GHSA-4pfg-2mw5-f8jx
was published
for
@cloudflare/vite-plugin
(npm)
Jul 8, 2025
Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection
High
CVE-2025-53372
was published
for
node-code-sandbox-mcp
(npm)
Jul 8, 2025
fastapi-guard is vulnerable to ReDoS through inefficient regex
Moderate
CVE-2025-53539
was published
for
fastapi-guard
(pip)
Jul 7, 2025
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Low
CVE-2025-53535
was published
for
better-auth
(npm)
Jul 7, 2025
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
High
CVE-2025-6209
was published
for
llama-index-core
(pip)
Jul 7, 2025
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Moderate
CVE-2025-5472
was published
for
llama-index-core
(pip)
Jul 7, 2025
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
Moderate
CVE-2025-6210
was published
for
llama-index-readers-obsidian
(pip)
Jul 7, 2025
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
High
CVE-2025-6386
was published
for
lollms
(pip)
Jul 7, 2025
LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
High
CVE-2025-3046
was published
for
llama-index-readers-obsidian
(pip)
Jul 7, 2025
LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
Moderate
CVE-2025-3044
was published
for
llama-index-readers-papers
(pip)
Jul 7, 2025
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
High
CVE-2025-3225
was published
for
llama-index-readers-papers
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Moderate
CVE-2025-3262
was published
for
transformers
(pip)
Jul 7, 2025
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
Moderate
CVE-2025-3263
was published
for
transformers
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its get_imports() function
Moderate
CVE-2025-3264
was published
for
transformers
(pip)
Jul 7, 2025
Transformers's Improper Input Validation vulnerability can be exploited through username injection
Low
CVE-2025-3777
was published
for
transformers
(pip)
Jul 7, 2025
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
Moderate
CVE-2025-3108
was published
for
llama-index-core
(pip)
Jul 7, 2025
Rust Web Push is vulnerable to a DoS attack via a large integer in a Content-Length header
Moderate
CVE-2025-53604
was published
for
web-push
(Rust)
Jul 5, 2025
rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
CVE-2025-53605
was published
for
protobuf
(Rust)
Jul 5, 2025
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
High
CVE-2025-53366
was published
for
mcp
(pip)
Jul 4, 2025
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
High
CVE-2025-53365
was published
for
mcp
(pip)
Jul 4, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
Cockpit - Content Platform vulnerable to XSS through name or email argument names
Moderate
CVE-2025-7053
was published
for
cockpit-hq/cockpit
(Composer)
Jul 4, 2025
Citizen Short Description stored XSS vulnerability through wikitext
High
CVE-2025-53369
was published
for
starcitizentools/short-description
(Composer)
Jul 3, 2025
Bolt CMS vulnerable to authenticated remote code execution
High
CVE-2025-34086
was published
for
bolt/bolt
(Composer)
Jul 3, 2025
ProTip!
Advisories are also available from the
GraphQL API