Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

14,706 advisories

Loading
sm1ee Credited to sm1ee
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner Moderate
GHSA-9cmh-xcqm-5hqr was published for n8n (npm) Jul 22, 2026
thesecguy45 Credited to thesecguy45
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
GHSA-89vp-jrxv-24w8 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab PluginManager lock-rule enforcement bypass Moderate
GHSA-h5v5-8746-g7mm was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
Next.js: Cache confusion of response bodies for requests with bodies Moderate
CVE-2026-64648 was published for next (npm) Jul 22, 2026
rafabd1 Credited to rafabd1
yorukot Credited to yorukot
Next.js: Unbounded Server Action payload in Edge runtime Moderate
CVE-2026-64646 was published for next (npm) Jul 22, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
Next.js: Unauthenticated disclosure of internal Server Function endpoints Moderate
CVE-2026-64643 was published for next (npm) Jul 22, 2026
randomguy6407 Credited to randomguy6407
Eclipse Jetty: Path parameter traversal Moderate
CVE-2026-8384 was published for org.eclipse.jetty:jetty-util (Maven) Jul 22, 2026
jweny Credited to jweny
Eclipse Jetty: HTTP Authority/Host mismatch Moderate
CVE-2026-6790 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections Moderate
CVE-2026-10051 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data Moderate
CVE-2026-65589 was published for n8n (npm) Jul 22, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions Moderate
CVE-2026-59941 was published for dompdf/dompdf (Composer) Jul 22, 2026
riodrwn Credited to riodrwn
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction Moderate
CVE-2026-59820 was published for litellm (pip) Jul 22, 2026
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook Moderate
CVE-2026-65014 was published for n8n (npm) Jul 22, 2026
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction Moderate
CVE-2026-65596 was published for n8n (npm) Jul 22, 2026
34selen Credited to 34selen
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows Moderate
CVE-2026-65590 was published for n8n (npm) Jul 22, 2026
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads Moderate
CVE-2026-58661 was published for n8n (npm) Jul 22, 2026
CodeByMoriarty Credited to CodeByMoriarty
HO-9 Credited to HO-9
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials Moderate
CVE-2026-59254 was published for n8n (npm) Jul 22, 2026
ProTip! Advisories are also available from the GraphQL API