Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,103 advisories

Loading
manus-use Credited to manus-use
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing High
GHSA-jwjp-4649-v8jp was published for SIPSorcery (NuGet) Aug 12, 2026
manus-use Credited to manus-use
Nadav0077 Credited to Nadav0077 and igorpyan igorpyan igorpyan
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62902 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62871 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability High
CVE-2026-62897 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability High
CVE-2026-70354 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability High
CVE-2026-62886 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability High
CVE-2026-62901 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability Moderate
CVE-2026-62899 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability High
CVE-2026-62898 was published for Microsoft.NETCore.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow Moderate
CVE-2026-53466 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 31, 2026
Bin-infinite Credited to Bin-infinite
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability High
CVE-2026-32203 was published for System.Security.Cryptography.Xml (NuGet) Jul 28, 2026
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS) High
CVE-2026-54632 was published for SIPSorcery (NuGet) Jul 28, 2026
Lougarou Credited to Lougarou
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
kongzhenhit-code Credited to kongzhenhit-code
ImageMagick: Heap Buffer Over-Write in fx operation Moderate
CVE-2026-62363 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
Kwstubbs Credited to Kwstubbs
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided Moderate
CVE-2026-62343 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
Kwstubbs Credited to Kwstubbs
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) Moderate
GHSA-p5rm-jg5c-8c77 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
gavinbarron Credited to gavinbarron and gn00295120 gn00295120 gn00295120
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName High
CVE-2026-59866 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` Critical
CVE-2026-59865 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, gavinbarron, baywet, and mohammad228 mrostamipoor mrostamipoor
gavinbarron gavinbarron baywet baywet mohammad228 mohammad228
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF High
CVE-2026-59863 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-59867 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Critical
CVE-2026-59864 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, jingjingjia-ms, and baywet mrostamipoor mrostamipoor
jingjingjia-ms jingjingjia-ms baywet baywet
ProTip! Advisories are also available from the GraphQL API