Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
Keycloak: UMA Policy Resource Injection Allows Unauthorized Cross-User Permission Grants High
CVE-2026-4636 was published for org.keycloak:keycloak-services (Maven) Apr 2, 2026
Authorization bypass in Quarkus High
CVE-2023-6394 was published for io.quarkus:quarkus-smallrye-graphql-client (Maven) Dec 9, 2023
cescoffier Credited to cescoffier
Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources High
CVE-2021-28165 was published for org.eclipse.jetty:jetty-server (Maven) Apr 6, 2021
ProTip! Advisories are also available from the GraphQL API