Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

109 advisories

Loading
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
PyJWT: PyJWKClient follows redirects when fetching JWKS High
CVE-2026-102267 was published for PyJWT (pip) Sep 29, 2026
NovaHunter06 Credited to NovaHunter06
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer High
CVE-2026-102677 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
Alleysira Credited to Alleysira
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery High
CVE-2026-63127 was published for rmcp (Rust) Sep 16, 2026
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check High
GHSA-mf7q-r4rv-jv94 was published for github.com/crossplane/crossplane-runtime/v2 (Go) Aug 27, 2026
tonghuaroot Credited to tonghuaroot and bugbunny-research bugbunny-research bugbunny-research
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header High
CVE-2026-54167 was published for github.com/openshift-pipelines/pipelines-as-code (Go) Aug 20, 2026
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage High
CVE-2026-53728 was published for @medplum/core (npm) Aug 17, 2026
sAjibuu Credited to sAjibuu
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in High
GHSA-qq9h-g4jm-xgf3 was published for better-auth (npm) Jul 24, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login High
GHSA-8342-988q-86cr was published for n8n (npm) Jul 22, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability High
CVE-2026-47304 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
rbhanda Credited to rbhanda
melange: Incomplete package integrity verification allows data section substitution High
CVE-2026-54174 was published for chainguard.dev/apko (Go) Jul 10, 2026
xnox Credited to xnox and egibs egibs egibs
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email High
CVE-2026-53516 was published for better-auth (npm) Jul 7, 2026
avrmeduard Credited to avrmeduard
widavies Credited to widavies
OpenClaw: Trusted retry endpoint checks could match hostname prefixes High
GHSA-77q5-rr5v-x43q was published for openclaw (npm) Jul 2, 2026
ccy41928-del Credited to ccy41928-del
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components High
CVE-2026-44937 was published for github.com/rancher/fleet (Go) Jul 1, 2026
Gogs: LFS dedupe path leaks private repo content across tenants High
CVE-2026-52812 was published for gogs.io/gogs (Go) Jun 23, 2026
amwhoi Credited to amwhoi
ProTip! Advisories are also available from the GraphQL API