Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

47 advisories

Loading
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization Moderate
CVE-2026-86818 was published for fast-uri (npm) Sep 29, 2026
manus-use Credited to manus-use, mcollina, UlisesGascon, and manus-pi mcollina mcollina
UlisesGascon UlisesGascon manus-pi manus-pi
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing Moderate
GHSA-g57g-f23g-4646 was published for nodemailer (npm) Sep 29, 2026
ZeroXJacks Credited to ZeroXJacks
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content Moderate
GHSA-p634-w6r4-rjp2 was published for adm-zip (npm) Sep 29, 2026
zikk090 Credited to zikk090
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain Moderate
GHSA-wmmp-3585-3rmp was published for nodemailer (npm) Sep 8, 2026
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning Moderate
CVE-2026-73846 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Mail: Email address spoofing via malformed RFC 2047 encoded-words Moderate
CVE-2026-63435 was published for mail (RubyGems) Sep 2, 2026
mantas Credited to mantas and glefait glefait glefait
rampage0010 Credited to rampage0010, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation Moderate
CVE-2026-59882 was published for guzzlehttp/psr7 (Composer) Jul 21, 2026
GrahamCampbell Credited to GrahamCampbell
netfoil has a domain name filter bypass via multiple questions Moderate
GHSA-59qp-cfj3-rp64 was published for github.com/tinfoil-factory/netfoil (Go) Jul 7, 2026
Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host Moderate
CVE-2026-47076 was published for hackney (Erlang) Jun 26, 2026
Ganbagana Credited to Ganbagana and maennchen maennchen maennchen
kexinoh Credited to kexinoh, russellb, jperezdealgaba, and DarkLight1337 russellb russellb
jperezdealgaba jperezdealgaba DarkLight1337 DarkLight1337
nicolas-grekas Credited to nicolas-grekas and 0xEr3n 0xEr3n 0xEr3n
Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification Moderate
CVE-2026-45066 was published for symfony/html-sanitizer (Composer) May 27, 2026
Next.js vulnerable to cache poisoning in React Server Component responses Moderate
CVE-2026-44576 was published for next (npm) May 11, 2026
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters Moderate
CVE-2026-30246 was published for github.com/gofiber/fiber/v3 (Go) Apr 28, 2026
xeloxa Credited to xeloxa, gaby, and ReneWerner87 gaby gaby
ReneWerner87 ReneWerner87
justhtml has sanitization bypass in custom policies and programmatic DOM Moderate
GHSA-vrx2-77f2-ww34 was published for justhtml (pip) Apr 22, 2026
EmilStenstrom Credited to EmilStenstrom
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing Moderate
CVE-2026-32762 was published for rack (RubyGems) Apr 2, 2026
th4s1s Credited to th4s1s, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass. Moderate
CVE-2026-26961 was published for rack (RubyGems) Apr 2, 2026
CodeByMoriarty Credited to CodeByMoriarty, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Duplicate Advisory: OpenClaw: system.run approval identity mismatch could execute a different binary than displayed Moderate
GHSA-mxmg-3p7m-2ghr was published for openclaw (npm) Mar 21, 2026 • withdrawn
astral-tokio-tar insufficiently validates PAX extensions during extraction Moderate
CVE-2026-32766 was published for astral-tokio-tar (Rust) Mar 17, 2026
woodruffw Credited to woodruffw and xokdvium xokdvium xokdvium
OpenClaw: system.run allow-always persistence included shell-commented payload tails Moderate
GHSA-9q2p-vc84-2rwm was published for openclaw (npm) Mar 9, 2026
tdjackey Credited to tdjackey
OpenClaw has exec allowlist/safeBins policy-runtime mismatch via env -S wrapper interpretation Moderate
GHSA-796m-2973-wc5q was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
ProTip! Advisories are also available from the GraphQL API