Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

259 advisories

Loading
Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext Moderate
CVE-2026-68969 was published for apache-airflow (pip) Aug 12, 2026
oscerd Credited to oscerd
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values Moderate
GHSA-fj2x-mqqp-3v2w was published for trigger.dev (npm) Oct 2, 2026
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API Moderate
CVE-2025-37727 was published for org.elasticsearch.plugin:reindex-client (Maven) Oct 10, 2025
sealonohana Credited to sealonohana
foreman-mcp-server Inserts Sensitive Information into Log File Moderate
CVE-2026-9073 was published for foreman-mcp-server (pip) Jun 23, 2026
OpenBao Agent Writes Secrets to Stdout Low
CVE-2026-77285 was published for github.com/openbao/openbao (Go) Sep 22, 2026
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs Low
CVE-2026-81870 was published for go.opentelemetry.io/otel/exporters/otlp/otlptrace (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
Jupyter Server: 5xx request logging leaks token-bearing Referer header values High
CVE-2026-86049 was published for jupyter_server (pip) Sep 17, 2026
DavidCarliez Credited to DavidCarliez, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages High
CVE-2026-61798 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (Maven) Aug 20, 2026
sondt99 Credited to sondt99
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File High
CVE-2026-34487 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Apr 9, 2026
aruneko Credited to aruneko and antonbombov antonbombov antonbombov
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Moderate
CVE-2026-54704 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
FWinkler79 Credited to FWinkler79
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics Low
GHSA-2625-rw7m-5q5x was published for hubuum_client (Rust) Jul 24, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data Moderate
CVE-2026-65589 was published for n8n (npm) Jul 22, 2026
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data Moderate
GHSA-fmvg-vhqq-r2mj was published for n8n (npm) Jul 22, 2026 • withdrawn
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) Moderate
CVE-2026-59947 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router Moderate
CVE-2026-54236 was published for vllm (pip) Jun 17, 2026
SnailSploit Credited to SnailSploit and jperezdealgaba jperezdealgaba jperezdealgaba
vLLM has RCE In Video Processing Critical
CVE-2026-22778 was published for vllm (pip) Feb 2, 2026
dan-sec-ops Credited to dan-sec-ops, DarkLight1337, and russellb DarkLight1337 DarkLight1337
russellb russellb
Calico Inserts Sensitive Information into Log File High
CVE-2026-6720 was published for github.com/projectcalico/calicoctl/v3 (Go) May 28, 2026
Calico Inserts Sensitive Information into Log File Moderate
CVE-2026-41184 was published for github.com/projectcalico/calico (Go) May 28, 2026
Calico Inserts Sensitive Information into Log File Moderate
CVE-2026-41185 was published for github.com/projectcalico/calico (Go) May 28, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs Moderate
GHSA-q683-8468-r6h6 was published for web-auth/webauthn-symfony-bundle (Composer) Jun 26, 2026
Git credentials are exposed in Atlantis logs High
CVE-2024-52009 was published for github.com/runatlantis/atlantis (Go) Nov 8, 2024
niooss-ledger Credited to niooss-ledger and cookesan cookesan cookesan
ProTip! Advisories are also available from the GraphQL API