Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

149 advisories

Loading
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
CVE-2026-73419 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
Netty has Insufficient Bailiwick Validation for NS Records High
CVE-2026-47691 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records High
CVE-2026-45674 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit High
CVE-2026-54007 was published for open-webui (pip) Jun 17, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, grumpinout1, and Classic298 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1 Classic298 Classic298
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts Moderate
CVE-2026-55767 was published for guzzlehttp/guzzle (Composer) Jun 19, 2026
iliaal Credited to iliaal and EchoTydes EchoTydes EchoTydes
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Moderate
CVE-2026-70599 was published for electron (npm) Aug 5, 2026
offset Credited to offset
Guzzle: Noncanonical cookie domain keeps subdomain scope Moderate
CVE-2026-69245 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
GrahamCampbell Credited to GrahamCampbell
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection Moderate
CVE-2026-63118 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot, dodge1218, and hewei-gikaku dodge1218 dodge1218
hewei-gikaku hewei-gikaku
gun_http2 has an Origin Validation Error vulnerability Moderate
CVE-2026-43972 was published for gun (Erlang) Jun 8, 2026
OAuth: Cross-origin token-request redirects can expose signed request metadata High
CVE-2026-54605 was published for oauth (RubyGems) Jul 28, 2026
pboling Credited to pboling
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution High
CVE-2026-59208 was published for n8n (npm) Jul 22, 2026
bearsyankees Credited to bearsyankees
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack Moderate
CVE-2026-46611 was published for glances (pip) Jun 22, 2026
sectroyer Credited to sectroyer
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path Critical
GHSA-g53w-w6mj-hrpp was published for github.com/Kuadrant/mcp-gateway (Go) May 19, 2026
Bhuvanesh66 Credited to Bhuvanesh66
Guzzle: Cookie Disclosure and Injection via IP-Address Domains Moderate
CVE-2026-59883 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
rexpository Credited to rexpository
sanic-cors contains an improper regular expression in the try_match() function Moderate
CVE-2026-37737 was published for sanic-cors (pip) Jun 5, 2026
MCP Python SDK: WebSocket server transport does not support Host/Origin validation High
CVE-2026-59950 was published for mcp (pip) Jul 16, 2026
nitish-yaddala Credited to nitish-yaddala, Nadav0077, dodge1218, gistrec, and u-ktdi Nadav0077 Nadav0077
dodge1218 dodge1218 gistrec gistrec u-ktdi u-ktdi
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass High
CVE-2026-50168 was published for @angular/platform-server (npm) Jun 15, 2026
alan-agius4 Credited to alan-agius4, AndrewKushnir, josephperrott, and 0xEr3n AndrewKushnir AndrewKushnir
josephperrott josephperrott 0xEr3n 0xEr3n
Anki's local HTTP server does not sufficiently validate requests High
CVE-2026-59153 was published for aqt (pip) Jun 19, 2026
taviso Credited to taviso
vittorio-prodomo Credited to vittorio-prodomo, mo-getter, benjaminpkane, kevin-dimichel, AdonaiVera, and AAtomical mo-getter mo-getter
benjaminpkane benjaminpkane kevin-dimichel kevin-dimichel AdonaiVera AdonaiVera AAtomical AAtomical
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim Low
CVE-2026-37977 was published for org.keycloak:keycloak-services (Maven) Apr 6, 2026
ahus1 Credited to ahus1
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist Critical
CVE-2026-54069 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
oduoke567 Credited to oduoke567
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing Moderate
CVE-2026-55438 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle High
CVE-2026-55487 was published for pnpm (npm) Jun 26, 2026
ProTip! Advisories are also available from the GraphQL API