Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

195 advisories

Loading
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an... Critical Unreviewed
CVE-2026-72590 was published Aug 10, 2026
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines Moderate
CVE-2026-71311 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
undici vulnerable to CRLF Injection via blob-like body 'type' property Moderate
CVE-2026-15157 was published for undici (npm) Aug 3, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type Moderate
CVE-2026-49756 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows... Moderate Unreviewed
CVE-2026-57511 was published Jul 28, 2026
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder Moderate
CVE-2026-59921 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty Moderate
CVE-2026-59920 was published for io.netty:netty-codec-stomp (Maven) Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address Moderate
CVE-2026-59919 was published for io.netty:netty-codec-haproxy (Maven) Jul 22, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs Moderate
CVE-2026-42258 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server High
GHSA-7cx2-g3h9-382p was published for crawl4ai (pip) Jun 16, 2026
guzzlehttp/psr7 has CRLF Injection via URI Host Component Moderate
CVE-2026-49214 was published for guzzlehttp/psr7 (Composer) Jun 11, 2026
edorian Credited to edorian
Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param` Low
CVE-2026-48596 was published for tesla (Erlang) Jul 10, 2026
PJUllrich Credited to PJUllrich, yordis, and maennchen yordis yordis
maennchen maennchen
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target` Low
CVE-2026-48861 was published for mint (Erlang) Jul 9, 2026
PJUllrich Credited to PJUllrich, maennchen, and ericmj maennchen maennchen
ericmj ericmj
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address Moderate
CVE-2026-53533 was published for aiosmtplib (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
Net::IMAP: Command Injection via ID command argument Moderate
CVE-2026-47242 was published for net-imap (RubyGems) Jun 9, 2026
nevans Credited to nevans
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument Moderate
CVE-2026-47240 was published for net-imap (RubyGems) Jun 9, 2026
nevans Credited to nevans
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. Moderate Unreviewed
CVE-2026-1502 was published Apr 10, 2026
ProTip! Advisories are also available from the GraphQL API