Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,606 advisories

Loading
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
LF Edge eKuiper: Self-XSS in External Service Creation Low
CVE-2025-24978 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
multer vulnerable to file size limit bypass via async fileFilter race condition Low
CVE-2026-77063 was published for multer (npm) Sep 8, 2026
ThinkerHao Credited to ThinkerHao, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
joi: Prototype pollution via a `__proto__` language key in custom messages Low
CVE-2026-84368 was published for @hapi/joi (npm) Sep 8, 2026
tihanyin Credited to tihanyin and mordamin mordamin mordamin
joi: object().rename() with a template target can set the validated object's prototype Low
CVE-2026-84367 was published for joi (npm) Sep 8, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher Low
CVE-2026-73087 was published for github.com/amir20/dozzle (Go) Sep 8, 2026
Josh-TantoSec Credited to Josh-TantoSec
CKAN MCP Server: Information disclosure via verbose error reflection Low
CVE-2026-73844 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
ImageMagick: Memory Leak when providing invalid options to the cli Low
GHSA-cvhv-g4rq-3hmw was published for Magick.NET-Q16-AnyCPU (NuGet) Sep 2, 2026
007bsd Credited to 007bsd and Junaid-PK Junaid-PK Junaid-PK
Filament: Password validity disclosure for accounts denied panel access on login page Low
CVE-2026-84307 was published for filament/filament (Composer) Sep 1, 2026
danharrin Credited to danharrin
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter Low
CVE-2026-42350 was published for github.com/akuity/kargo (Go) Aug 27, 2026
PontusHanssen Credited to PontusHanssen, krancour, and rpelczar krancour krancour
rpelczar rpelczar
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Low
CVE-2026-54713 was published for cakephp/queue (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
netfoil vulnerable to improper handling of untrusted DoH response data Low
GHSA-4ph6-mjv7-3fq6 was published for github.com/tinfoil-factory/netfoil (Go) Aug 24, 2026
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure Low
CVE-2026-71514 was published for nltk (pip) Aug 22, 2026
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints Low
GHSA-rxhg-vcww-2mpw was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
axel-corsiez Credited to axel-corsiez
ProTip! Advisories are also available from the GraphQL API