Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

45 advisories

Loading
MagicMirror: ssrf calendar .js Moderate
CVE-2026-63643 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an... Moderate Unreviewed
CVE-2026-72640 was published Aug 13, 2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` Moderate
CVE-2026-54663 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
Astro: Unauthenticated path override in the @astrojs/vercel ISR function Moderate
CVE-2026-73424 was published for @astrojs/vercel (npm) Jul 20, 2026
jp-soba Credited to jp-soba
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access Moderate
CVE-2026-55430 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies Moderate
CVE-2026-9595 was published for webpack-dev-server (npm) Jun 17, 2026
bjohansebas Credited to bjohansebas and UlisesGascon UlisesGascon UlisesGascon
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint Moderate
CVE-2026-53931 was published for nocodb (npm) Jun 17, 2026
p- Credited to p-
KEIJOT Credited to KEIJOT and shaked-seal shaked-seal shaked-seal
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities Moderate
CVE-2026-50169 was published for @angular/service-worker (npm) Jun 15, 2026
Yenya030 Credited to Yenya030, alan-agius4, JeanMeche, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott AndrewKushnir AndrewKushnir
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection Moderate
CVE-2026-47122 was published for github.com/sparkle-project/Sparkle (Swift) May 29, 2026
fg0x0 Credited to fg0x0
Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts Moderate
GHSA-5jgm-f9wr-9qm7 was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests Moderate
GHSA-4mhr-cxr4-2prm was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API Moderate
GHSA-8pf2-vj79-4wxg was published for openclaw (npm) Apr 28, 2026 withdrawn
Kratos has a Confused Deputy issue Moderate
CVE-2026-6993 was published for github.com/go-kratos/kratos/v2 (Go) Apr 25, 2026
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource Moderate
CVE-2026-39961 was published for github.com/aiven/aiven-operator (Go) Apr 10, 2026
AndresAIFR Credited to AndresAIFR
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF Moderate
CVE-2025-62718 was published for axios (npm) Apr 9, 2026
AmeerAssadi Credited to AmeerAssadi, SwTan98, and jasonsaayman SwTan98 SwTan98
jasonsaayman jasonsaayman
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path` Moderate
CVE-2026-33768 was published for @astrojs/vercel (npm) Mar 26, 2026
jp-soba Credited to jp-soba
OliveTin's RestartAction always runs actions as guest Moderate
CVE-2026-30225 was published for github.com/OliveTin/OliveTin (Go) Mar 5, 2026
Zwique Credited to Zwique
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries Moderate
CVE-2025-68944 was published for code.gitea.io/gitea (Go) Dec 26, 2025
ProTip! Advisories are also available from the GraphQL API