Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,175 advisories

Loading
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages High
CVE-2026-61798 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (Maven) Aug 20, 2026
sondt99 Credited to sondt99
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with... Moderate Unreviewed
CVE-2026-76374 was published Aug 20, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with... Moderate Unreviewed
CVE-2026-76375 was published Aug 20, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for... Moderate Unreviewed
CVE-2026-75485 was published Aug 18, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in... Moderate Unreviewed
CVE-2026-68969 was published Aug 12, 2026
ProTip! Advisories are also available from the GraphQL API