Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

17 advisories

Loading
Class Loading Vulnerability in Artemis High
CVE-2024-23682 was published for de.tum.in.ase:artemis-java-test-sandbox (Maven) Feb 9, 2022
juliuskreutz Credited to juliuskreutz
The Bare Metal Operator (BMO) can expose particularly named secrets from other namespaces via BMH CRD Moderate
CVE-2024-43803 was published for github.com/metal3-io/baremetal-operator (Go) Sep 3, 2024
Azure PromptFlow remote code execution related to Jinja templates Moderate
CVE-2025-24986 was published for promptflow-core (pip) Mar 11, 2025
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD Moderate
CVE-2025-29781 was published for github.com/metal3-io/baremetal-operator/apis (Go) Mar 17, 2025
WHALEEYE Credited to WHALEEYE and debuggerchen debuggerchen debuggerchen
ingress-nginx admission controller RCE escalation Critical
CVE-2025-1974 was published for k8s.io/ingress-nginx (Go) Mar 25, 2025
dor-hayun Credited to dor-hayun
Apache Syncope allows malicious administrators to inject Groovy code High
CVE-2025-57738 was published for org.apache.syncope.core:syncope-core-spring (Maven) Oct 20, 2025
DSPy does not properly restrict file reads Moderate
CVE-2025-12695 was published for dspy (pip) Nov 4, 2025
MCP Run Python has a Sandbox Escape & Server Takeover Vulnerability Moderate
CVE-2026-25905 was published for mcp-run-python (pip) Feb 9, 2026
saivarun3407 Credited to saivarun3407
Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw High
CVE-2026-4282 was published for org.keycloak:keycloak-services (Maven) Apr 2, 2026
Keycloak: Replay of action tokens via improper handling of single-use entries Moderate
CVE-2026-4325 was published for org.keycloak:keycloak-services (Maven) Apr 2, 2026
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes Moderate
CVE-2026-34775 was published for electron (npm) Apr 3, 2026
pretix: API leaks check-in data between events of the same organizer Moderate
CVE-2026-5600 was published for pretix (pip) Apr 8, 2026
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding Moderate
CVE-2026-41174 was published for github.com/traefik/traefik (Go) Apr 24, 2026
tamemghq Credited to tamemghq
Spring gRPC SecurityContext leaks across requests upon authorization failure Moderate
CVE-2026-40968 was published for org.springframework.grpc:spring-grpc (Maven) Apr 28, 2026
Apache Syncope has an Improper Isolation or Compartmentalization vulnerability High
CVE-2026-42782 was published for org.apache.syncope.core:syncope-core-spring (Maven) May 26, 2026
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients High
CVE-2026-57135 was published for praisonai (npm) Jun 18, 2026
rexpository Credited to rexpository
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Moderate
CVE-2026-71325 was published for github.com/traefik/traefik (Go) Aug 6, 2026
ttzero25 Credited to ttzero25
ProTip! Advisories are also available from the GraphQL API