Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

169 advisories

Loading
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values Moderate
GHSA-fj2x-mqqp-3v2w was published for trigger.dev (npm) Oct 2, 2026
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext Moderate
CVE-2026-68969 was published for apache-airflow (pip) Aug 12, 2026
oscerd Credited to oscerd
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Moderate
CVE-2026-54704 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
FWinkler79 Credited to FWinkler79
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data Moderate
CVE-2026-65589 was published for n8n (npm) Jul 22, 2026
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data Moderate
GHSA-fmvg-vhqq-r2mj was published for n8n (npm) Jul 22, 2026 • withdrawn
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) Moderate
CVE-2026-59947 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs Moderate
GHSA-q683-8468-r6h6 was published for web-auth/webauthn-symfony-bundle (Composer) Jun 26, 2026
foreman-mcp-server Inserts Sensitive Information into Log File Moderate
CVE-2026-9073 was published for foreman-mcp-server (pip) Jun 23, 2026
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router Moderate
CVE-2026-54236 was published for vllm (pip) Jun 17, 2026
SnailSploit Credited to SnailSploit and jperezdealgaba jperezdealgaba jperezdealgaba
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs) Moderate
CVE-2026-47768 was published for github.com/juev/nebula-mesh (Go) Jun 10, 2026
ak2k Credited to ak2k
Admidio writes session IDs and auto-login cookie values to application logs Moderate
CVE-2026-47234 was published for admidio/admidio (Composer) May 29, 2026
0x2face Credited to 0x2face, spect3r1, 0xreizouko, ADHAM-KHAIRY, BabaYaga0x01, 00xCanelo, and 0xheg3zy spect3r1 spect3r1
0xreizouko 0xreizouko ADHAM-KHAIRY ADHAM-KHAIRY BabaYaga0x01 BabaYaga0x01 00xCanelo 00xCanelo 0xheg3zy 0xheg3zy
Calico Inserts Sensitive Information into Log File Moderate
CVE-2026-41184 was published for github.com/projectcalico/calico (Go) May 28, 2026
Calico Inserts Sensitive Information into Log File Moderate
CVE-2026-41185 was published for github.com/projectcalico/calico (Go) May 28, 2026
OpenBao's Inline Auth Incorrectly Redacted Headers Moderate
CVE-2026-46358 was published for github.com/openbao/openbao (Go) May 28, 2026
jackyliao123 Credited to jackyliao123
Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions Moderate
GHSA-5wxr-w449-57cm was published for shivammathur/setup-php (GitHub Actions) May 20, 2026
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode Moderate
CVE-2026-45581 was published for org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim (Maven) May 19, 2026
lalalala5678 Credited to lalalala5678 and bestbeforetoday bestbeforetoday bestbeforetoday
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages Moderate
CVE-2026-45679 was published for go.opentelemetry.io/obi (Go) May 18, 2026
MrAlias Credited to MrAlias and grcevski grcevski grcevski
Apache Airflow Providers OpenSearch: OpenSearch task-log handler leaks credentials embedded in the host URL Moderate
CVE-2026-43826 was published for apache-airflow-providers-opensearch (pip) May 11, 2026
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL Moderate
CVE-2026-41018 was published for apache-airflow-providers-elasticsearch (pip) May 11, 2026
Spring Cloud Config Server Logged Sensitive Information Moderate
CVE-2026-41004 was published for org.springframework.cloud:spring-cloud-config-server (Maven) May 7, 2026
scottfrederick Credited to scottfrederick
Vercel: Non-interactive mode includes CLI arguments in suggested command output Moderate
CVE-2026-44479 was published for vercel (npm) May 7, 2026
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode Moderate
CVE-2026-42282 was published for n8n-mcp (npm) Apr 25, 2026
Mirr2 Credited to Mirr2
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests Moderate
CVE-2026-41495 was published for n8n-mcp (npm) Apr 23, 2026
S4nso Credited to S4nso
ProTip! Advisories are also available from the GraphQL API