Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

47 advisories

Loading
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Arena task endpoints can bypass underlying model access controls Moderate
CVE-2026-59225 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Moderate
CVE-2026-59212 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
smoke-wolf Credited to smoke-wolf, rexpository, and Classic298 rexpository rexpository
Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
ImageMagick: Policy Bypass in script operation due to missing checks Low
GHSA-vghg-5jrg-2398 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check Low
GHSA-v3j6-27vc-7pw2 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Heap-use-after-free via XMP profile could result in a crash Low
GHSA-qh5g-q395-cx4j was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219 Moderate
GHSA-56m6-8q75-f2rw was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass in concatenate operation due to missing checks Moderate
CVE-2026-55628 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments Moderate
CVE-2026-55597 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Infinite Loop in connected-components when providing invalid arguments Moderate
CVE-2026-55595 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Stack Overflow in MVG decoder due to missing depth check. Moderate
CVE-2026-55594 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
CVE-2026-73416 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab PluginManager lock-rule enforcement bypass Moderate
GHSA-h5v5-8746-g7mm was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read Moderate
CVE-2026-55646 was published for vllm (pip) Jul 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
rexpository Credited to rexpository
rexpository Credited to rexpository
rexpository Credited to rexpository
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining High
CVE-2026-57133 was published for praisonai (npm) Jun 18, 2026
rexpository Credited to rexpository
npm PraisonAI AgentLoop onToolCall approval runs after tool execution High
CVE-2026-57137 was published for praisonai (npm) Jun 18, 2026
rexpository Credited to rexpository
ProTip! Advisories are also available from the GraphQL API