Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters Moderate
CVE-2026-44587 was published for carrierwave (RubyGems) May 27, 2026
snoopysecurity Credited to snoopysecurity and bilerden bilerden bilerden
Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247 Low
GHSA-8678-w3jw-xfc2 was published for nokogiri (RubyGems) Jun 19, 2026
bilerden Credited to bilerden
protobufjs: Denial of Service via infinite loop in .proto option parsing Moderate
CVE-2026-59877 was published for protobufjs (npm) Jul 20, 2026
bilerden Credited to bilerden
Axios: Prototype pollution gadgets can alter axios request construction Moderate
GHSA-mmx7-hfxf-jppx was published for axios (npm) Jul 20, 2026
bilerden Credited to bilerden
ProTip! Advisories are also available from the GraphQL API