Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName High
CVE-2026-59866 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator High
CVE-2026-59859 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
peombwa Credited to peombwa and thegr1ffyn thegr1ffyn thegr1ffyn
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator High
CVE-2026-59862 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator High
CVE-2026-59861 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection High
CVE-2026-59860 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
thegr1ffyn Credited to thegr1ffyn, gavinbarron, and peombwa gavinbarron gavinbarron
peombwa peombwa
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability High
CVE-2026-50650 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Jul 21, 2026
Kiota: Code Generation Literal Injection High
CVE-2026-41134 was published for Microsoft.OpenApi.Kiota (NuGet) Apr 14, 2026
baywet Credited to baywet and gavinbarron gavinbarron gavinbarron
Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability High
CVE-2024-21643 was published for Microsoft.IdentityModel.Protocols.SignedHttpRequest (NuGet) Jan 9, 2024
rymeskar Credited to rymeskar, brentschmaltz, GeoK, keegan-caruso, jmprieur, jennyf19, and TimHannMSFT brentschmaltz brentschmaltz
GeoK GeoK keegan-caruso keegan-caruso jmprieur jmprieur jennyf19 jennyf19 TimHannMSFT TimHannMSFT
.NET Remote Code Execution Vulnerability High
CVE-2022-41089 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Dec 14, 2022
tdunlap607 Credited to tdunlap607
Code Injection in Masuit.Tools.Core High
CVE-2022-21167 was published for Masuit.Tools.Core (NuGet) May 3, 2022
ProTip! Advisories are also available from the GraphQL API