Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

106 advisories

Loading
MagicMirror: ssrf calendar .js Moderate
CVE-2026-63643 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
Astro: Unauthenticated path override in the @astrojs/vercel ISR function Moderate
CVE-2026-73424 was published for @astrojs/vercel (npm) Jul 20, 2026
jp-soba Credited to jp-soba
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an... Moderate Unreviewed
CVE-2026-72640 was published Aug 13, 2026
KEIJOT Credited to KEIJOT and shaked-seal shaked-seal shaked-seal
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` Moderate
CVE-2026-54663 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary... Critical Unreviewed
CVE-2026-42933 was published Jul 24, 2026
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint Moderate
CVE-2026-53931 was published for nocodb (npm) Jun 17, 2026
p- Credited to p-
widavies Credited to widavies
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints Critical
CVE-2026-53513 was published for @better-auth/sso (npm) Jul 7, 2026
vaadata-poyetont Credited to vaadata-poyetont
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities Moderate
CVE-2026-50169 was published for @angular/service-worker (npm) Jun 15, 2026
Yenya030 Credited to Yenya030, alan-agius4, JeanMeche, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott AndrewKushnir AndrewKushnir
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access Moderate
CVE-2026-55430 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration High
CVE-2026-49821 was published for github.com/fission/fission (Go) Jun 30, 2026
j311yl0v3u Credited to j311yl0v3u, b0b0haha, and sanketsudake b0b0haha b0b0haha
sanketsudake sanketsudake
Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator` High
CVE-2026-55225 was published for io.strimzi:strimzi (Maven) Jun 18, 2026
cherez0ff Credited to cherez0ff, ppatierno, scholzj, and katheris ppatierno ppatierno
scholzj scholzj katheris katheris
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies Moderate
CVE-2026-9595 was published for webpack-dev-server (npm) Jun 17, 2026
bjohansebas Credited to bjohansebas and UlisesGascon UlisesGascon UlisesGascon
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs) High
CVE-2026-53999 was published for github.com/radius-project/radius (Go) Jun 12, 2026
b0b0haha Credited to b0b0haha and j311yl0v3u j311yl0v3u j311yl0v3u
ProTip! Advisories are also available from the GraphQL API