Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

146 advisories

Loading
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
rclone: Verbose Stack Trace Disclosure in RC API Error Responses Low
GHSA-gwfq-86j8-7qhv was published for github.com/rclone/rclone (Go) Aug 5, 2026
SnailSploit Credited to SnailSploit and ncw ncw ncw
X1AOxiang Credited to X1AOxiang
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile High
CVE-2026-73409 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath Moderate
CVE-2026-54561 was published for mcp-memory-keeper (npm) Jul 17, 2026
mcfly-zzh Credited to mcfly-zzh
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state Moderate
GHSA-qcr8-x557-7cp3 was published for @asymmetric-effort/specifyjs (npm) Jul 2, 2026
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages Moderate
GHSA-6g9v-7gq3-p2c6 was published for surrealdb (Rust) Jul 1, 2026
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter High
GHSA-cc8f-fcx3-gpjr was published for surrealdb (Rust) Jun 19, 2026
kah-ja Credited to kah-ja
canto-saas-api: OAuth credentials exposed in URL query string and exception messages Moderate
CVE-2026-55375 was published for jleehr/canto-saas-api (Composer) Jun 19, 2026
jleehr Credited to jleehr
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token Critical
CVE-2026-48039 was published for meta-ads-mcp (pip) Jun 11, 2026
232-323 Credited to 232-323
Spring Web Services: SOAP security faults leak Spring Security account state Moderate
CVE-2026-40997 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
Spring Data REST potentially exposes persistence-layer internals to HTTP clients Moderate
CVE-2026-41730 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic Low
CVE-2026-45723 was published for github.com/siderolabs/omni (Go) Jun 5, 2026
bugbunny-research Credited to bugbunny-research
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers Moderate
CVE-2026-47248 was published for parse-server (npm) May 29, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Keycloak Generates an Error Message Containing Sensitive Information Moderate
CVE-2026-9794 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
Algernon: Single-file mode unconditionally enables debug mode High
CVE-2026-45728 was published for github.com/xyproto/algernon (Go) May 19, 2026
Dredsen Credited to Dredsen
Vaadin Build Plugins is Affected by a Possible Information Disclosure Vulnerability Low
CVE-2026-7860 was published for com.vaadin:flow-gradle-plugin (Maven) May 19, 2026
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak Moderate
CVE-2026-44002 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information High
CVE-2026-42459 was published for github.com/free5gc/udm (Go) May 7, 2026
Giancannella Credited to Giancannella
Flight vulnerable to sensitive information disclosure via default error handler High
CVE-2026-42552 was published for flightphp/core (Composer) May 6, 2026
Rootingg Credited to Rootingg
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI Moderate
CVE-2026-44226 was published for pyload-ng (pip) May 6, 2026
ProTip! Advisories are also available from the GraphQL API