Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,538 advisories

Loading
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers Moderate
CVE-2026-86079 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service Moderate
CVE-2026-86078 was published for n8n (npm) Sep 10, 2026
Masofgon Credited to Masofgon
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Moderate
CVE-2026-86994 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
hiddingtrojans Credited to hiddingtrojans
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket Moderate
CVE-2026-86077 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
Traefik: ForwardAuth identity spoofing via dot-form header alias Moderate
CVE-2026-88011 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
velgusgus599 Credited to velgusgus599
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded Moderate
CVE-2026-88012 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ShadMalloy Credited to ShadMalloy
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements High
CVE-2026-88060 was published for @angular/platform-server (npm) Sep 10, 2026
mabjr33 Credited to mabjr33 and alan-agius4 alan-agius4 alan-agius4
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR High
CVE-2026-88056 was published for @angular/platform-server (npm) Sep 10, 2026
alan-agius4 Credited to alan-agius4 and Adyej999 Adyej999 Adyej999
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` Moderate
CVE-2026-88059 was published for @angular/common (npm) Sep 10, 2026
JeanMeche Credited to JeanMeche, alan-agius4, and SkyZeroZx alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx
SkyZeroZx Credited to SkyZeroZx, josephperrott, alan-agius4, and JeanMeche josephperrott josephperrott
alan-agius4 alan-agius4 JeanMeche JeanMeche
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration High
CVE-2026-55416 was published for pimcore/pimcore (Composer) Sep 10, 2026
EclipsSec Credited to EclipsSec
yadhukrishnam Credited to yadhukrishnam
Masofgon Credited to Masofgon
Masofgon Credited to Masofgon
Masofgon Credited to Masofgon
Classic298 Credited to Classic298
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint Moderate
CVE-2026-87994 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
manus-use Credited to manus-use and Classic298 Classic298 Classic298
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader High
CVE-2026-87996 was published for open-webui (pip) Sep 10, 2026
baeseungwon1010 Credited to baeseungwon1010 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions Moderate
CVE-2026-87997 was published for open-webui (pip) Sep 10, 2026
whyiug Credited to whyiug and Classic298 Classic298 Classic298
Bellingham-max Credited to Bellingham-max and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch High
CVE-2026-87999 was published for open-webui (pip) Sep 10, 2026
NaorYaa Credited to NaorYaa and Classic298 Classic298 Classic298
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange Moderate
CVE-2026-88005 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation High
CVE-2026-59161 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
ProTip! Advisories are also available from the GraphQL API