Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,094 advisories

Loading
Emissary has a Path Traversal via Blacklist Bypass in Configuration API Moderate
CVE-2026-35583 was published for gov.nsa.emissary:emissary (Maven) Apr 8, 2026
BrennanTM Credited to BrennanTM
Emissary has Stored XSS via Navigation Template Link Injection Moderate
CVE-2026-35571 was published for gov.nsa.emissary:emissary (Maven) Apr 7, 2026
BrennanTM Credited to BrennanTM
Keycloak: Replay of action tokens via improper handling of single-use entries Moderate
CVE-2026-4325 was published for org.keycloak:keycloak-services (Maven) Apr 2, 2026
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *) Moderate
CVE-2026-34237 was published for io.modelcontextprotocol.sdk:mcp-core (Maven) Mar 30, 2026
srikanthramu Credited to srikanthramu
FHIR Validator: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing Moderate
CVE-2026-34360 was published for ca.uhn.hapi.fhir:org.hl7.fhir.core (Maven) Mar 30, 2026
offset Credited to offset
Keycloak: Missing Role Enforcement on UMA 2.0 Permission Ticket Endpoint Leads to Information Disclosure Moderate
CVE-2026-3190 was published for org.keycloak:keycloak-model-jpa (Maven) Mar 26, 2026
Keycloak: manage-clients permission escalates to full realm admin access Moderate
CVE-2026-3121 was published for org.keycloak:keycloak-services (Maven) Mar 26, 2026
sbt: Source dependency feature (via crafted VCS URL) leads to arbitrary code execution on Windows Moderate
CVE-2026-32948 was published for org.scala-sbt:sbt (Maven) Mar 24, 2026
anatoliykmetyuk Credited to anatoliykmetyuk and eed3si9n eed3si9n eed3si9n
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests Moderate
CVE-2026-3260 was published for io.undertow:undertow-core (Maven) Mar 24, 2026
Keycloak has Improper Access Control allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false Moderate
CVE-2026-4628 was published for org.keycloak:keycloak-services (Maven) Mar 23, 2026
Spring Framework Improper Path Limitation with Script View Templates Moderate
CVE-2026-22737 was published for org.springframework:spring-webflux (Maven) Mar 20, 2026
Jenkins LoadNinja Plugin does not mask LoadNinja API keys displayed on the job configuration form Moderate
CVE-2026-33004 was published for org.jenkins-ci.plugins:loadninja (Maven) Mar 18, 2026
Jenkins LoadNinja Plugin stores LoadNinja API keys unencrypted in job config.xml files Moderate
CVE-2026-33003 was published for org.jenkins-ci.plugins:loadninja (Maven) Mar 18, 2026
Keycloak: Denial of Service due to excessive SAMLRequest decompression Moderate
CVE-2026-2575 was published for org.keycloak:keycloak-saml-adapter-core (Maven) Mar 18, 2026
Apache Livy: Unauthorized directory access Moderate
CVE-2025-66249 was published for org.apache.livy:livy-server (Maven) Mar 13, 2026
Apache Livy: Restrict file access Moderate
CVE-2025-60012 was published for org.apache.livy:livy-server (Maven) Mar 13, 2026
Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API Moderate
CVE-2026-3429 was published for org.keycloak:keycloak-services (Maven) Mar 11, 2026
Ankush-Pathak Credited to Ankush-Pathak
Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash Moderate
CVE-2026-2742 was published for com.vaadin:flow-server (Maven) Mar 10, 2026
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function Moderate
CVE-2026-23907 was published for org.apache.pdfbox:pdfbox-examples (Maven) Mar 10, 2026
Cloudfoundry UAA has logic error in the token revocation endpoint implementation Moderate
CVE-2026-22723 was published for org.cloudfoundry.identity:cloudfoundry-identity-server (Maven) Mar 5, 2026
Apache ActiveMQ is Vulnerable to Integer Overflow or Wraparound Moderate
CVE-2025-66168 was published for org.apache.activemq:activemq-all (Maven) Mar 4, 2026
Apache Ranger Vulnerable to Improper Validation of Certificate with Host Mismatch Moderate
CVE-2025-59060 was published for org.apache.ranger:ranger-nifi-registry-plugin (Maven) Mar 3, 2026
PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages Moderate
CVE-2026-28338 was published for net.sourceforge.pmd:pmd-core (Maven) Feb 28, 2026
smaranchand Credited to smaranchand
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-72hv-8253-57qq was published for com.fasterxml.jackson.core:jackson-core (Maven) Feb 28, 2026
sprabhav7 Credited to sprabhav7, rohan-repos, neilmadden-hazelcast, and awsactran rohan-repos rohan-repos
neilmadden-hazelcast neilmadden-hazelcast awsactran awsactran
Junrar has an arbitrary file write due to backslash Path Traversal bypass in LocalFolderExtractor on Linux/Unix Moderate
CVE-2026-28208 was published for com.github.junrar:junrar (Maven) Feb 27, 2026
Cache-Money Credited to Cache-Money
ProTip! Advisories are also available from the GraphQL API