Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,552 advisories

Loading
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader High
CVE-2026-87996 was published for open-webui (pip) Sep 10, 2026
baeseungwon1010 Credited to baeseungwon1010 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions Moderate
CVE-2026-87997 was published for open-webui (pip) Sep 10, 2026
whyiug Credited to whyiug and Classic298 Classic298 Classic298
Bellingham-max Credited to Bellingham-max and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch High
CVE-2026-87999 was published for open-webui (pip) Sep 10, 2026
NaorYaa Credited to NaorYaa and Classic298 Classic298 Classic298
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange Moderate
CVE-2026-88005 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation High
CVE-2026-59161 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows Moderate
CVE-2026-59162 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name High
GHSA-x7m8-jrm8-hpvx was published for @eigenpal/docx-editor-core (npm) Sep 10, 2026
samcorcos Credited to samcorcos
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree Moderate
CVE-2026-88000 was published for open-webui (pip) Sep 9, 2026
Classic298 Credited to Classic298
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets Moderate
CVE-2026-88001 was published for open-webui (pip) Sep 9, 2026
arpitjain099 Credited to arpitjain099 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history Moderate
CVE-2026-88002 was published for open-webui (pip) Sep 9, 2026
YashvantHange Credited to YashvantHange and Classic298 Classic298 Classic298
CyberKareem Credited to CyberKareem
@openhop/server: Path Traversal in Flow ID File Operations High
CVE-2026-59179 was published for @openhop/server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import High
CVE-2026-59176 was published for functype-mcp-server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
Joker linter executed project-local .jokerd/linter.* files during linting High
CVE-2026-59172 was published for github.com/candid82/joker (Go) Sep 9, 2026
Komari: Management Interface CSRF High
GHSA-hxjg-93wc-h8p8 was published for github.com/komari-monitor/komari (Go) Sep 9, 2026
GuangChen2333 Credited to GuangChen2333
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run High
CVE-2026-59160 was published for @yeger/turbo-graph (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients High
CVE-2026-59158 was published for nuxt-ollama (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
webhookd: Unrestricted HTTP Header to Shell Variable Injection Moderate
CVE-2026-59157 was published for github.com/ncarlier/webhookd (Go) Sep 9, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool High
CVE-2026-55864 was published for org.geonetwork-opensource:gn-web-app (Maven) Sep 9, 2026
castilho101 Credited to castilho101, ethiack-admin, juanluisrp, and jodygarnett ethiack-admin ethiack-admin
juanluisrp juanluisrp jodygarnett jodygarnett
smol-toml: Denial of Service via malformed TOML documents High
CVE-2026-85730 was published for smol-toml (npm) Sep 9, 2026
Ravi-lk Credited to Ravi-lk
weasyprint Has Server-Side Request Forgery (SSRF) Moderate
CVE-2026-55073 was published for weasyprint (pip) Sep 9, 2026
ko41a Credited to ko41a
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list` Moderate
CVE-2026-54529 was published for sqladmin (pip) Sep 9, 2026
muslimbek-0x Credited to muslimbek-0x
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service Moderate
CVE-2026-53495 was published for github.com/containerd/containerd (Go) Sep 9, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
ProTip! Advisories are also available from the GraphQL API