GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,093 advisories
Filter by severity
HPACK Denial of Service vulnerability (HPACK Bomb)
High
CVE-2016-6581
was published
for
hpack
(pip)
Jul 5, 2019
Django Denial-of-service by filling session store
High
CVE-2015-5143
was published
for
Django
(pip)
Jul 5, 2019
High severity vulnerability that affects postfix-mta-sts-resolver
High
CVE-2019-16791
was published
for
postfix-mta-sts-resolver
(pip)
Jul 5, 2019
Deserialization vulnerability exists in parso
High
CVE-2019-12760
was published
for
parso
(pip)
Jun 13, 2019
•
withdrawn
Improper Input Validation in Google TensorFlow
High
CVE-2018-7577
was published
for
tensorflow
(pip)
Apr 30, 2019
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
High
CVE-2018-10055
was published
for
tensorflow
(pip)
Apr 30, 2019
Improper Restriction of Operations within the Bounds of a Memory Buffer in Google TensorFlow
High
CVE-2018-8825
was published
for
tensorflow
(pip)
Apr 24, 2019
Improper Input Validation in python-dbusmock
High
CVE-2015-1326
was published
for
python-dbusmock
(pip)
Apr 23, 2019
Improper Certificate Validation in urllib3
High
CVE-2019-11324
was published
for
urllib3
(pip)
Apr 19, 2019
Apache Airflow vulnerable to CSRF Attacks
High
CVE-2019-0229
was published
for
apache-airflow
(pip)
Apr 18, 2019
SQLAlchemy is vulnerable to SQL Injection via group_by parameter
High
CVE-2019-7548
was published
for
SQLAlchemy
(pip)
Apr 16, 2019
Jinja2 sandbox escape via string formatting
High
CVE-2019-10906
was published
for
Jinja2
(pip)
Apr 10, 2019
High severity vulnerability that affects Jinja2
High
CVE-2016-10745
was published
for
Jinja2
(pip)
Apr 10, 2019
CoAPthon3 vulnerable to Deserialization of Untrusted Data
High
CVE-2018-12679
was published
for
CoAPthon3
(pip)
Apr 8, 2019
Moderate severity vulnerability that affects splunk-sdk
High
CVE-2019-5729
was published
for
splunk-sdk
(pip)
Mar 25, 2019
Improper Input Validation python-gnupg
High
CVE-2019-6690
was published
for
python-gnupg
(pip)
Mar 25, 2019
Webargs mishandles concurrent JSON parsing
High
CVE-2019-9710
was published
for
webargs
(pip)
Mar 12, 2019
Uncontrolled Memory Consumption in Django
High
CVE-2019-6975
was published
for
Django
(pip)
Feb 12, 2019
Pylons Colander Denial of Service vulnerability
High
CVE-2017-18361
was published
for
colander
(pip)
Feb 7, 2019
Improper Certificate Validation in Apache Airflow
High
CVE-2018-20245
was published
for
apache-airflow
(pip)
Jan 25, 2019
Cross-Site Request Forgery (CSRF) in Apache Airflow
High
CVE-2017-17835
was published
for
apache-airflow
(pip)
Jan 25, 2019
Improper Input Validation in Apache Airflow resulting in Remote Code Execution
High
CVE-2017-15720
was published
for
apache-airflow
(pip)
Jan 25, 2019
ProTip!
Advisories are also available from the
GraphQL API