Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

172 advisories

Loading
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header Moderate
CVE-2026-55087 was published for ep_etherpad-lite (npm) Aug 13, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability Moderate
CVE-2026-62899 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
h2: Duplicate Host header could facilitate request smuggling Moderate
CVE-2026-71554 was published for h2 (pip) Aug 6, 2026
SunandM Credited to SunandM
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool High
CVE-2026-71324 was published for github.com/traefik/traefik (Go) Aug 6, 2026
xclow3n Credited to xclow3n
AIOHTTP: HTTP request smuggling via WebSocket upgrade Moderate
CVE-2026-69243 was published for aiohttp (pip) Aug 3, 2026
shivams0099 Credited to shivams0099 and Dreamsorcerer Dreamsorcerer Dreamsorcerer
undici vulnerable to downstream response desynchronization via retry interceptor Moderate
CVE-2026-16728 was published for undici (npm) Aug 3, 2026
samuel871211 Credited to samuel871211, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) High
CVE-2026-73495 was published for org.http4s:blaze-http_2.12 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser High
CVE-2026-73494 was published for org.http4s:blaze-http_2.13 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
swift-nio-http2: Missing CR/LF/NUL validation in header values Moderate
CVE-2026-64785 was published for swift-nio-http2 (Swift) Jul 24, 2026
sour-exploit Credited to sour-exploit
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass Moderate
CVE-2026-59900 was published for io.netty:netty-codec-http2 (Maven) Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation Moderate
CVE-2026-59898 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
mint: Content-Length header accepts non-RFC "+" sign prefix Moderate
CVE-2026-49753 was published for mint (Erlang) Jul 9, 2026
PJUllrich Credited to PJUllrich, ericmj, and maennchen ericmj ericmj
maennchen maennchen
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests High
CVE-2026-50197 was published for github.com/zalando/skipper (Go) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling High
CVE-2026-48979 was published for php-standard-library/h2 (Composer) Jun 26, 2026
azjezz Credited to azjezz
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact` Moderate
GHSA-jrpc-7vxp-69p6 was published for org.http4k:http4k-core (Maven) Jun 19, 2026
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` High
CVE-2026-52845 was published for github.com/caddyserver/caddy (Go) Jun 16, 2026
Vincent550102 Credited to Vincent550102 and dunglas dunglas dunglas
vLLM: OpenAI auth bypass Critical
CVE-2026-48746 was published for vllm (pip) Jun 16, 2026
x41j Credited to x41j, russellb, and DarkLight1337 russellb russellb
DarkLight1337 DarkLight1337
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted Moderate
CVE-2026-50020 was published for io.netty:netty-codec-http (Maven) Jun 15, 2026
chrisvest Credited to chrisvest
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling Low
CVE-2026-53538 was published for python-multipart (pip) Jun 15, 2026
maxisbey Credited to maxisbey
SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec Moderate
CVE-2026-28898 was published for github.com/apple/swift-nio-http2 (Swift) Jun 12, 2026
kuranikaran Credited to kuranikaran and maheshwarivijaykumar maheshwarivijaykumar maheshwarivijaykumar
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux Moderate
CVE-2026-41853 was published for org.springframework:spring-webflux (Maven) Jun 9, 2026
Rootingg Credited to Rootingg
x41j Credited to x41j, ehhthing, and nic-lovin ehhthing ehhthing
nic-lovin nic-lovin
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Low
CVE-2026-46342 was published for @nuxt/nitro-server (npm) May 19, 2026
fancymalware Credited to fancymalware
ProTip! Advisories are also available from the GraphQL API