Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,562 advisories

Loading
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Ruby json: JSON generator heap buffer overflow when streaming to an IO Low
CVE-2026-54696 was published for json (RubyGems) Jul 23, 2026
susdrip Credited to susdrip
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks Low
CVE-2026-59821 was published for litellm (pip) Jul 22, 2026
yaaras Credited to yaaras
LiteLLM: Local file read via request-supplied OIDC file references Low
CVE-2026-59819 was published for litellm (pip) Jul 22, 2026
Dompdf: File existence oracle via font-face stylesheet declaration Low
CVE-2026-55555 was published for dompdf/dompdf (Composer) Jul 22, 2026
g4nkd Credited to g4nkd
Dompdf: Chroot Validation Bypass Low
CVE-2026-55554 was published for dompdf/dompdf (Composer) Jul 22, 2026
vxhex Credited to vxhex and snoopysecurity snoopysecurity snoopysecurity
MoonFuji Credited to MoonFuji
Gitea: Webhook Authorization Header Returned in Plaintext via API Low
CVE-2026-58511 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service Low
CVE-2026-55984 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
Gitea: Private Repository Metadata Remains Accessible After Access Revocation Low
CVE-2026-58434 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim Low
CVE-2026-23603 was published for code.gitea.io/gitea (Go) Jul 21, 2026
alimezar Credited to alimezar, Vext-Labs, theluckystrike, prakhar0x01, AnuragBathani, and khoadb175 Vext-Labs Vext-Labs
theluckystrike theluckystrike prakhar0x01 prakhar0x01 AnuragBathani AnuragBathani khoadb175 khoadb175
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
connorshea Credited to connorshea
sec-reex Credited to sec-reex and LlewxamDev LlewxamDev LlewxamDev
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
File Browser: Share API exposes the password hash and bypass token Low
CVE-2026-62684 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code Low
GHSA-rjwr-m7qx-3fjr was published for github.com/oapi-codegen/oapi-codegen/v2 (Go) Jul 17, 2026
quart27219 Credited to quart27219 and kimdu0 kimdu0 kimdu0
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof Low
CVE-2026-54542 was published for nimiq-primitives (Rust) Jul 16, 2026
paberr Credited to paberr and Piravlos Piravlos Piravlos
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys Low
CVE-2026-54541 was published for nimiq-primitives (Rust) Jul 16, 2026
paberr Credited to paberr and Piravlos Piravlos Piravlos
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) Low
CVE-2026-58196 was published for github.com/stacklok/toolhive (Go) Jul 15, 2026
bIackr0se Credited to bIackr0se, jhrozek, JAORMX, ChrisJBurns, and rdimitrov jhrozek jhrozek
JAORMX JAORMX ChrisJBurns ChrisJBurns rdimitrov rdimitrov
ProTip! Advisories are also available from the GraphQL API