Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

917 advisories

Loading
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
GHSA-p279-2cqp-84jg was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback Critical
CVE-2026-62379 was published for org.openidentityplatform.openam:openam-core (Maven) Jul 24, 2026
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass Critical
CVE-2026-62263 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jul 24, 2026
Pig-Tail Credited to Pig-Tail, MarkLee131, baradika, manus-use, and tonghuaroot MarkLee131 MarkLee131
baradika baradika manus-use manus-use tonghuaroot tonghuaroot
fastjson has a remote code execution (RCE) vulnerability Critical
CVE-2026-16723 was published for com.alibaba:fastjson (Maven) Jul 23, 2026
dor-hayun Credited to dor-hayun, AnvithaCDhanekula, and timtebeek AnvithaCDhanekula AnvithaCDhanekula
timtebeek timtebeek
oscerd Credited to oscerd
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered  gridfs.*  HTTP headers Critical
CVE-2026-48204 was published for org.apache.camel:camel-mongodb-gridfs (Maven) Jul 6, 2026
oscerd Credited to oscerd
LaunchServer FileServerHandler has an unauthenticated path traversal issue Critical
CVE-2026-54617 was published for pro.gravit.launcher:launchserver-api (Maven) Jul 2, 2026
getclaude Credited to getclaude
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints Critical
CVE-2026-45052 was published for org.openidentityplatform.openam:openam-federation-library (Maven) Jun 24, 2026
wodzen Credited to wodzen
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage Critical
CVE-2026-45051 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jun 24, 2026
wodzen Credited to wodzen
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI Critical
CVE-2026-46495 was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jun 22, 2026
wodzen Credited to wodzen
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl) Critical
CVE-2026-44203 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jun 22, 2026
gujjuboy10x00 Credited to gujjuboy10x00 and wodzen wodzen wodzen
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro Critical
CVE-2026-44179 was published for com.xwiki.pro:xwiki-pro-macros (Maven) Jun 22, 2026
michitux Credited to michitux
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete) Critical
CVE-2026-57168 was published for io.openremote:openremote-manager (Maven) Jun 19, 2026
Forklit Credited to Forklit and vladkoniakhinmob vladkoniakhinmob vladkoniakhinmob
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory Critical
CVE-2026-55471 was published for ca.uhn.hapi.fhir:org.hl7.fhir.utilities (Maven) Jun 17, 2026
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure Critical
CVE-2026-32966 was published for org.apache.dolphinscheduler:dolphinscheduler-api (Maven) Jun 17, 2026
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks Critical
CVE-2026-32967 was published for org.apache.dolphinscheduler:dolphinscheduler-api (Maven) Jun 17, 2026
Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve path Critical
CVE-2026-50076 was published for org.apache.fory:fory-core (Maven) Jun 4, 2026
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass Critical
CVE-2026-47065 was published for org.apache.mina:mina-core (Maven) Jun 3, 2026
Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection Critical
CVE-2026-46621 was published for org.yamcs:yamcs-core (Maven) May 27, 2026
superpegaso2703 Credited to superpegaso2703
Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override Critical
CVE-2026-46562 was published for org.yamcs:yamcs-core (Maven) May 27, 2026
2BCEB1 Credited to 2BCEB1
Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory` Critical
CVE-2026-44632 was published for org.yamcs:yamcs-core (Maven) May 27, 2026
superpegaso2703 Credited to superpegaso2703
XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName} Critical
CVE-2026-33137 was published for org.xwiki.platform:xwiki-platform-rest-server (Maven) May 26, 2026
odgrso Credited to odgrso
XWiki Platform has path traversal via resources parameter in ssx and jsx endpoints when using leading slash Critical
CVE-2026-23734 was published for org.xwiki.commons:xwiki-commons-classloader-api (Maven) May 26, 2026
majkelstick Credited to majkelstick
ProTip! Advisories are also available from the GraphQL API