Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,104 advisories

Loading
ImageMagick: Memory Leak when providing invalid options to the cli Low
GHSA-cvhv-g4rq-3hmw was published for Magick.NET-Q16-AnyCPU (NuGet) Sep 2, 2026
007bsd Credited to 007bsd
ImageMagick: Memory Leak in multiple coders that write raw pixel data Moderate
CVE-2026-56368 was published for Magick.NET-Q16-AnyCPU (NuGet) Feb 25, 2026
ylwango613 Credited to ylwango613
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer, awsactran, and sgracia714 awsactran awsactran
sgracia714 sgracia714
Nadav0077 Credited to Nadav0077 and igorpyan igorpyan igorpyan
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) Moderate
CVE-2026-73851 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
gavinbarron Credited to gavinbarron, gn00295120, and BarakSrour gn00295120 gn00295120
BarakSrour BarakSrour
Kiota: Code Generation Literal Injection High
CVE-2026-41134 was published for Microsoft.OpenApi.Kiota (NuGet) Apr 14, 2026
baywet Credited to baywet and gavinbarron gavinbarron gavinbarron
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-59867 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName High
CVE-2026-59866 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` Critical
CVE-2026-59865 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, gavinbarron, baywet, and mohammad228 mrostamipoor mrostamipoor
gavinbarron gavinbarron baywet baywet mohammad228 mohammad228
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Critical
CVE-2026-59864 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, jingjingjia-ms, and baywet mrostamipoor mrostamipoor
jingjingjia-ms jingjingjia-ms baywet baywet
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF High
CVE-2026-59863 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator High
CVE-2026-59859 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
peombwa Credited to peombwa and thegr1ffyn thegr1ffyn thegr1ffyn
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator High
CVE-2026-59862 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator High
CVE-2026-59861 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection High
CVE-2026-59860 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
thegr1ffyn Credited to thegr1ffyn, gavinbarron, and peombwa gavinbarron gavinbarron
peombwa peombwa
manus-use Credited to manus-use
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing High
GHSA-jwjp-4649-v8jp was published for SIPSorcery (NuGet) Aug 12, 2026
manus-use Credited to manus-use
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62902 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62871 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability High
CVE-2026-62897 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability High
CVE-2026-70354 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62886 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability High
CVE-2026-62901 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability Moderate
CVE-2026-62899 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
ProTip! Advisories are also available from the GraphQL API