Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15,029 advisories

Loading
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints Moderate
CVE-2026-55156 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
232-323 Credited to 232-323
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL Moderate
CVE-2026-53722 was published for nuxt (npm) Jun 16, 2026
manop55555 Credited to manop55555, sota70, and sealonohana sota70 sota70
sealonohana sealonohana
alcls01111 Credited to alcls01111, cookesan, and sealonohana cookesan cookesan
sealonohana sealonohana
CakePHP Authentication: Open redirect weakness via backslash bypass Moderate
CVE-2026-55590 was published for cakephp/authentication (Composer) Jun 17, 2026
edorian Credited to edorian, markstory, and aquaturtlium markstory markstory
aquaturtlium aquaturtlium
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations Moderate
CVE-2026-53442 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container" Moderate
CVE-2026-53440 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins exposes other users' timezone and view names to users with Overall/Read permission Moderate
CVE-2026-53439 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins: Missing permission check allows unauthorized cancellation of queue items Moderate
CVE-2026-53438 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL Moderate
CVE-2026-53437 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
CVE-2026-73419 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Moderate
CVE-2026-64607 was published for org.apache.httpcomponents.client5:httpclient5 (Maven) Jul 31, 2026
Lueton Credited to Lueton
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization Moderate
CVE-2026-49844 was published for org.apache.logging.log4j:log4j-api (Maven) Jul 11, 2026
ppkarwasz Credited to ppkarwasz, ashwani945, and Lueton ashwani945 ashwani945
Lueton Lueton
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL Moderate
CVE-2026-53436 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
TypeORM: migration:generate template-literal code injection Moderate
CVE-2026-73651 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
CVE-2026-73648 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Quasar: Prototype pollution in the extend() utility Moderate
CVE-2026-73647 was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds. Moderate
CVE-2026-73645 was published for @openzeppelin/confidential-contracts (npm) Jan 5, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
CVE-2026-73565 was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API Moderate
CVE-2026-52815 was published for gogs.io/gogs (Go) Jun 23, 2026
oduoke567 Credited to oduoke567
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass Moderate
CVE-2026-73563 was published for @backstage/plugin-auth-backend (npm) Jul 24, 2026
ProTip! Advisories are also available from the GraphQL API