Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

917 advisories

Loading
carbon-apimgt does not properly restrict uploaded files Critical
CVE-2025-13590 was published for org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1 (Maven) Feb 19, 2026
sealbenb Credited to sealbenb
Jenkins GitHub Plugin has an XSS vulnerability Critical
CVE-2026-42523 was published for com.coravy.hudson.plugins.github:github (Maven) Apr 29, 2026
sealbenb Credited to sealbenb
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest Critical
CVE-2026-42027 was published for org.apache.opennlp:opennlp-tools (Maven) May 4, 2026
sealbenb Credited to sealbenb and maheshwarivijaykumar maheshwarivijaykumar maheshwarivijaykumar
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
CVE-2026-73644 was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
fastjson has a remote code execution (RCE) vulnerability Critical
CVE-2026-16723 was published for com.alibaba:fastjson (Maven) Jul 23, 2026
dor-hayun Credited to dor-hayun, AnvithaCDhanekula, and timtebeek AnvithaCDhanekula AnvithaCDhanekula
timtebeek timtebeek
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback Critical
CVE-2026-62379 was published for org.openidentityplatform.openam:openam-core (Maven) Jul 24, 2026
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases Critical
CVE-2026-44221 was published for com.arcadedb:arcadedb-server (Maven) May 5, 2026
sealbenb Credited to sealbenb
jinjava has Sandbox Bypass via JavaType-Based Deserialization Critical
CVE-2025-59340 was published for com.hubspot.jinjava:jinjava (Maven) Sep 17, 2025
taisehub Credited to taisehub, odgrso, jasmith-hs, and sealbenb odgrso odgrso
jasmith-hs jasmith-hs sealbenb sealbenb
OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution Critical
CVE-2026-33701 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Mar 25, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass Critical
CVE-2026-62263 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jul 24, 2026
Pig-Tail Credited to Pig-Tail, MarkLee131, baradika, manus-use, and tonghuaroot MarkLee131 MarkLee131
baradika baradika manus-use manus-use tonghuaroot tonghuaroot
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered  gridfs.*  HTTP headers Critical
CVE-2026-48204 was published for org.apache.camel:camel-mongodb-gridfs (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Fory Java SDK Has Deserialization of Untrusted Data in the Java replace-resolve path Critical
CVE-2026-50076 was published for org.apache.fory:fory-core (Maven) Jun 4, 2026
Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass Critical
CVE-2026-47065 was published for org.apache.mina:mina-core (Maven) Jun 3, 2026
Apache Derby: LDAP injection vulnerability in authenticator Critical
CVE-2022-46337 was published for org.apache.derby:derby (Maven) Nov 20, 2023
pdeslaur Credited to pdeslaur and theinfosecguy theinfosecguy theinfosecguy
Deserialization of Untrusted Data in Jython Critical
CVE-2016-4000 was published for org.python:jython (Maven) May 13, 2022
theinfosecguy Credited to theinfosecguy
LaunchServer FileServerHandler has an unauthenticated path traversal issue Critical
CVE-2026-54617 was published for pro.gravit.launcher:launchserver-api (Maven) Jul 2, 2026
getclaude Credited to getclaude
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete) Critical
CVE-2026-57168 was published for io.openremote:openremote-manager (Maven) Jun 19, 2026
Forklit Credited to Forklit and vladkoniakhinmob vladkoniakhinmob vladkoniakhinmob
Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks Critical
CVE-2025-14813 was published for org.bouncycastle:bcprov-debug-jdk14 (Maven) Apr 17, 2026
simon-reisinger-dynatrace Credited to simon-reisinger-dynatrace
Opendaylight will authenticate any username and password combination Critical
CVE-2015-1778 was published for org.opendaylight.odlparent:opendaylight-karaf-resources (Maven) May 17, 2022
simon-reisinger-dynatrace Credited to simon-reisinger-dynatrace
Apache CXF has an LDAP injection vulnerability Critical
CVE-2026-44930 was published for org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (Maven) May 26, 2026
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints Critical
CVE-2026-45052 was published for org.openidentityplatform.openam:openam-federation-library (Maven) Jun 24, 2026
wodzen Credited to wodzen
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage Critical
CVE-2026-45051 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jun 24, 2026
wodzen Credited to wodzen
ProTip! Advisories are also available from the GraphQL API