Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,552 advisories

Loading
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization High
CVE-2026-88008 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ihopenre-eng Credited to ihopenre-eng
Traefik entrypoint header-name sanitization bypassed via request trailers High
CVE-2026-88004 was published for github.com/traefik/traefik/v3 (Go) Sep 10, 2026
bipol4r Credited to bipol4r
Traefik HTTP/3 Backend NTLM Connection Reuse Critical
CVE-2026-88007 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
OneZ3r0 Credited to OneZ3r0
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace Moderate
CVE-2026-88014 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
manus-use Credited to manus-use and ncw ncw ncw
rclone local: crafted Range request against a translated symlink panics (DoS) Moderate
CVE-2026-88015 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass Critical
CVE-2026-88018 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: RC per-server auth-proxy bypass Critical
CVE-2026-88044 was published for github.com/rclone/rclone (Go) Sep 10, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: FTP cross-session auth-proxy backend confusion High
CVE-2026-88017 was published for github.com/rclone/rclone (Go) Sep 10, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: source object names can escape the configured root on upload Moderate
CVE-2026-88046 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: S3 multipart declared-length memory exhaustion High
CVE-2026-88045 was published for github.com/rclone/rclone (Go) Sep 10, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
galanko Credited to galanko and Classic298 Classic298 Classic298
DshtAnger Credited to DshtAnger and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle Moderate
CVE-2026-87013 was published for open-webui (pip) Sep 10, 2026
luida-ikura Credited to luida-ikura and Classic298 Classic298 Classic298
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes Moderate
CVE-2026-87014 was published for open-webui (pip) Sep 10, 2026
mtholmquist Credited to mtholmquist and Classic298 Classic298 Classic298
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission High
CVE-2026-59965 was published for @jhb.software/payload-alt-text-plugin (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
@argos-ci/core: CI Branch Name OS Command Injection High
CVE-2026-59960 was published for @argos-ci/core (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS High
GHSA-m3wp-48jr-vr4g was published for mistralrs-server-core (Rust) Sep 10, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication Moderate
CVE-2026-87015 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite High
CVE-2026-87016 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) Critical
CVE-2026-88062 was published for omniroute (npm) Sep 10, 2026
c111mb3r Credited to c111mb3r
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution Moderate
CVE-2026-86073 was published for n8n (npm) Sep 10, 2026
bariskececi Credited to bariskececi
ProTip! Advisories are also available from the GraphQL API