Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15 advisories

Loading
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login Moderate
CVE-2026-54338 was published for jupyterhub (pip) Aug 25, 2026
mauriceng98 Credited to mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk Zyy0530 Zyy0530
Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) Moderate
CVE-2026-54625 was published for django-cms (pip) Aug 24, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and mauriceng98 7thParkk 7thParkk
mauriceng98 mauriceng98
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) High
CVE-2026-54623 was published for django-cms (pip) Aug 24, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
django CMS: Structure endpoint bypasses page-view permission Moderate
CVE-2026-54624 was published for django-cms (pip) Aug 20, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
django CMS: Clipboard copy IDOR discloses unauthorized plugin content Moderate
CVE-2026-54622 was published for django-cms (pip) Aug 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and mauriceng98 7thParkk 7thParkk
mauriceng98 mauriceng98
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes Moderate
CVE-2026-59894 was published for sqlparse (pip) Aug 17, 2026
7thParkk Credited to 7thParkk
pypdf: Possible long runtimes/large memory usage for large CID font width ranges Moderate
CVE-2026-71852 was published for pypdf (pip) Aug 7, 2026
7thParkk Credited to 7thParkk and stefan6419846 stefan6419846 stefan6419846
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Socket.IO: Zero-attachment Memory Exhaustion High
CVE-2026-69185 was published for socket.io-parser (npm) Aug 3, 2026
aretekzs Credited to aretekzs, mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk mauriceng98 mauriceng98
Zyy0530 Zyy0530 Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header Moderate
CVE-2026-14631 was published for webpack-dev-server (npm) Jul 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, bjohansebas, Zyy0530, 7thParkk, and UlisesGascon bjohansebas bjohansebas
Zyy0530 Zyy0530 7thParkk 7thParkk UlisesGascon UlisesGascon
serde_with: KeyValueMap serialization panics on empty sequence or map entries Moderate
GHSA-7gcf-g7xr-8hxj was published for serde_with (Rust) Jul 15, 2026
7thParkk Credited to 7thParkk and iliana iliana iliana
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass Moderate
CVE-2026-55602 was published for http-proxy-middleware (npm) Jun 18, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, G-Rath, and ethantkoenig Zyy0530 Zyy0530
7thParkk 7thParkk G-Rath G-Rath ethantkoenig ethantkoenig
Deno: `fetch()` API sandbox bypass via missing DNS resolution check Moderate
CVE-2026-49859 was published for deno (Rust) Jun 16, 2026
alcls01111 Credited to alcls01111 and 7thParkk 7thParkk 7thParkk
ProTip! Advisories are also available from the GraphQL API