Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` High
CVE-2026-40110 was published for jupyter-server (pip) May 5, 2026
vnykmshr Credited to vnykmshr, Yann-P, and Carreau Yann-P Yann-P
Carreau Carreau
Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect Moderate
CVE-2026-34830 was published for rack (RubyGems) Apr 2, 2026
mzfr Credited to mzfr, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Rack has a root directory disclosure via unescaped regex interpolation in Rack::Directory Moderate
CVE-2026-34763 was published for rack (RubyGems) Apr 2, 2026
harukioya Credited to harukioya, ioquatix, and jeremyevans ioquatix ioquatix
jeremyevans jeremyevans
OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where... High Unreviewed
CVE-2026-32973 was published Mar 29, 2026
OpenClaw: Exec approval allowlist patterns overmatched on POSIX paths Moderate
GHSA-f8r2-vg7x-gh8m was published for openclaw (npm) Mar 13, 2026
zpbrent Credited to zpbrent
Keycloak Authorization Bypass vulnerability Moderate
CVE-2023-6544 was published for org.keycloak:keycloak-services (Maven) Apr 17, 2024
ProTip! Advisories are also available from the GraphQL API