Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

87 advisories

Loading
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath Moderate
CVE-2026-54561 was published for mcp-memory-keeper (npm) Jul 17, 2026
mcfly-zzh Credited to mcfly-zzh
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state Moderate
GHSA-qcr8-x557-7cp3 was published for @asymmetric-effort/specifyjs (npm) Jul 2, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages Moderate
GHSA-6g9v-7gq3-p2c6 was published for surrealdb (Rust) Jul 1, 2026
canto-saas-api: OAuth credentials exposed in URL query string and exception messages Moderate
CVE-2026-55375 was published for jleehr/canto-saas-api (Composer) Jun 19, 2026
jleehr Credited to jleehr
Spring Web Services: SOAP security faults leak Spring Security account state Moderate
CVE-2026-40997 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Spring Data REST potentially exposes persistence-layer internals to HTTP clients Moderate
CVE-2026-41730 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers Moderate
CVE-2026-47248 was published for parse-server (npm) May 29, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Keycloak Generates an Error Message Containing Sensitive Information Moderate
CVE-2026-9794 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak Moderate
CVE-2026-44002 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI Moderate
CVE-2026-44226 was published for pyload-ng (pip) May 6, 2026
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions` Moderate
CVE-2026-28786 was published for open-webui (pip) Mar 27, 2026
akshatgit Credited to akshatgit
free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions request Moderate
CVE-2026-33065 was published for github.com/free5gc/udm (Go) Mar 18, 2026
parse-server: Malformed `$regex` query leaks database error details in API response Moderate
CVE-2026-30835 was published for parse-server (npm) Mar 6, 2026
fancymalware Credited to fancymalware and mtrezza mtrezza mtrezza
Apache Airflow error reporting may expose full kwargs Moderate
CVE-2025-65995 was published for apache-airflow (pip) Feb 21, 2026
OpenClaw session tool visibility hardening and Telegram webhook secret fallback Moderate
CVE-2026-27004 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent Credited to aether-ai-agent
Withdrawn Advisory: Libredesk has a SSRF Vulnerability in Webhooks Moderate
CVE-2026-26957 was published for github.com/abhinavxd/libredesk (Go) Feb 18, 2026 withdrawn
PlayerIUnknown Credited to PlayerIUnknown
Directus Vulnerable to Information Leakage in Existing Collections Moderate
CVE-2025-64749 was published for @directus/api (npm) Nov 13, 2025
sbstn-k Credited to sbstn-k and kmzs kmzs kmzs
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers Moderate
GHSA-xvp7-8vm8-xfxx was published for @actual-app/sync-server (npm) Oct 20, 2025
StoobertB Credited to StoobertB and MatissJanis MatissJanis MatissJanis
ibexa/user login enumerates user accounts Moderate
GHSA-q3x8-6898-23g3 was published for ibexa/user (Composer) Oct 17, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function Moderate
CVE-2025-54291 was published for github.com/canonical/lxd (Go) Oct 2, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting Moderate
CVE-2025-43776 was published for com.liferay.portal:release.dxp.bom (Maven) Sep 9, 2025
ProTip! Advisories are also available from the GraphQL API