GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
354 advisories
Filter by severity
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
High
CVE-2025-27511
was published
for
org.geoserver.extension:gs-db2
(Maven)
Jun 11, 2026
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
High
CVE-2026-41731
was published
for
org.springframework.kafka:spring-kafka
(Maven)
Jun 10, 2026
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
High
CVE-2026-42211
was published
for
react-router
(npm)
Jun 3, 2026
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
High
CVE-2026-45077
was published
for
symfony/monolog-bridge
(Composer)
May 27, 2026
Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction
High
CVE-2026-45162
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
Graphite Has a Pickle Deserialization Vulnerability
High
GHSA-qw48-84f6-28gv
was published
for
graphitedb
(pip)
May 18, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
High
CVE-2026-45134
was published
for
langchain
(npm)
May 13, 2026
Snorkel BaseLabeler.load uses an unsafe pickle.load
High
CVE-2026-31223
was published
for
snorkel
(pip)
May 12, 2026
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
High
CVE-2026-31221
was published
for
pytorch-lightning
(pip)
May 12, 2026
Snorkel Trainer.load uses an unsafe torch.load
High
CVE-2026-31222
was published
for
snorkel
(pip)
May 12, 2026
Snorkel MultitaskClassifier.load uses an unsafe torch.load
High
CVE-2026-31224
was published
for
snorkel
(pip)
May 12, 2026
pgAdmin 4 has deserialization of untrusted data in its FileBackedSessionManager
High
CVE-2026-7818
was published
for
pgadmin4
(pip)
May 11, 2026
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
High
CVE-2026-44843
was published
for
langchain-core
(pip)
May 8, 2026
Apache Camel-Infinispan Component Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-40858
was published
for
org.apache.camel:camel-infinispan
(Maven)
Apr 27, 2026
Camel-MINA Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-40473
was published
for
org.apache.camel:camel-mina
(Maven)
Apr 27, 2026
Camel-PQC Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-40048
was published
for
org.apache.camel:camel-pqc
(Maven)
Apr 27, 2026
k8sGPT has Prompt Injection through its k8sGPT-Operator
High
GHSA-rp7v-4384-hfrp
was published
for
github.com/k8sgpt-ai/k8sgpt
(Go)
Apr 24, 2026
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
High
CVE-2026-41486
was published
for
ray
(pip)
Apr 24, 2026
camel-infinispan Vulnerable to Deserialization of Untrusted Data
High
CVE-2026-6857
was published
for
org.apache.camel:camel-infinispan
(Maven)
Apr 22, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
High
CVE-2026-25524
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
Apache Airflow allows code execution through crafted XCom payloads
High
CVE-2026-25917
was published
for
apache-airflow-core
(pip)
Apr 18, 2026
Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
High
CVE-2026-33858
was published
for
apache-airflow
(pip)
Apr 13, 2026
Keras has an untrusted deserialization vulnerability
High
CVE-2026-1462
was published
for
keras
(pip)
Apr 13, 2026
Apache Storm: Deserialization of Untrusted Data vulnerability
High
CVE-2026-35337
was published
for
org.apache.storm:storm-client
(Maven)
Apr 13, 2026
React Server Components have a Denial of Service Vulnerability
High
CVE-2026-23869
was published
for
react-server-dom-parcel
(npm)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API