Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,893 advisories

Loading
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) High
CVE-2026-54632 was published for SIPSorcery (NuGet) Jul 28, 2026
Lougarou Credited to Lougarou
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. Critical
CVE-2026-54588 was published for poweradmin/poweradmin (Composer) Jul 28, 2026
mike197312 Credited to mike197312
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
tonghuaroot Credited to tonghuaroot and pboling pboling pboling
OAuth: Cross-origin token-request redirects can expose signed request metadata High
CVE-2026-54605 was published for oauth (RubyGems) Jul 28, 2026
pboling Credited to pboling
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks Low
CVE-2026-54620 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity Low
CVE-2026-54619 was published for sqlite3 (RubyGems) Jul 28, 2026
cla7aye15I4nd Credited to cla7aye15I4nd
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
b-hermes Credited to b-hermes
0x7d8 Credited to 0x7d8
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities High
CVE-2026-55771 was published for com.cedarpolicy:cedar-java (Maven) Jul 28, 2026
@wakaru/cli arbitrary file write during bundle unpack High
CVE-2026-54545 was published for @wakaru/cli (npm) Jul 28, 2026
j4k0xb Credited to j4k0xb
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler High
CVE-2026-47427 was published for github.com/github/github-mcp-server (Go) Jul 28, 2026
manthanghasadiya Credited to manthanghasadiya
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC and rodrigoprimo rodrigoprimo rodrigoprimo
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
kodareef5 Credited to kodareef5
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages Moderate
CVE-2023-37465 was published for org.xwiki.contrib:discussions-server (Maven) Jul 27, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
GHSA-6vch-q96h-7gc3 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller Moderate
GHSA-8q49-2h5h-434x was published for @frontmcp/adapters (npm) Jul 24, 2026
EchoSkorJjj Credited to EchoSkorJjj and frontegg-david frontegg-david frontegg-david
ProTip! Advisories are also available from the GraphQL API