Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href Moderate
CVE-2026-25500 was published for rack (RubyGems) Feb 17, 2026
thesmartshadow Credited to thesmartshadow, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
hono/jsx does not isolate context per request, leading to cross-request data disclosure Moderate
CVE-2026-59896 was published for hono (npm) Jul 21, 2026
thesmartshadow Credited to thesmartshadow
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
ProTip! Advisories are also available from the GraphQL API