Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,303 advisories

Loading
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info High
CVE-2026-55157 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
mcfly-zzh Credited to mcfly-zzh
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets" High
CVE-2026-55153 was published for com.mchange:mchange-commons-java (Maven) Aug 14, 2026
4ra1n Credited to 4ra1n, unam4, and vmulas unam4 unam4
vmulas vmulas
OpenAM Insecure SSO Cookie Initialization High
CVE-2026-53660 was published for org.openidentityplatform.openam:openam-core (Maven) Aug 14, 2026
wodzen Credited to wodzen
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Grav: Unauthenticated denial of service via unbounded image derivative dimensions High
CVE-2026-53653 was published for getgrav/grav (Composer) Aug 14, 2026
iliaal Credited to iliaal
ldap3_proto has LDAP Filter stack exhaustion High
GHSA-qcxq-75wr-5cm8 was published for ldap3_proto (Rust) May 6, 2026
mbarbero Credited to mbarbero and micolous micolous micolous
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth and 36degrees 36degrees 36degrees
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist High
CVE-2026-35219 was published for @budibase/server (npm) Aug 14, 2026
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing High
CVE-2026-2332 was published for org.eclipse.jetty:jetty-http (Maven) Apr 14, 2026
xclow3n Credited to xclow3n, jhy, tlarionova-max, and ryanmurf jhy jhy
tlarionova-max tlarionova-max ryanmurf ryanmurf
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) High
CVE-2026-54513 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
fast-uri vulnerable to host confusion via failed IDN canonicalization High
CVE-2026-13676 was published for fast-uri (npm) Jul 21, 2026
celinke97 Credited to celinke97 and UlisesGascon UlisesGascon UlisesGascon
pyasn1 has a DoS vulnerability in decoder High
CVE-2026-23490 was published for pyasn1 (pip) Jan 16, 2026
tsigouris007 Credited to tsigouris007
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS High
CVE-2026-73654 was published for @trigger.dev/core (npm) Aug 13, 2026
MatiasTilleriasLey Credited to MatiasTilleriasLey
athuljayaram Credited to athuljayaram
Duplicate Advisory: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences High
GHSA-q5h6-fcf5-49g9 was published for nltk (pip) Jun 30, 2026 withdrawn
billchenchina Credited to billchenchina
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers High
CVE-2026-73418 was published for @auth/core (npm) Jul 23, 2026
deprrous Credited to deprrous
Genql: inject arbitrary JavaScript or TypeScript via a GraphQL schema High
CVE-2026-63397 was published for @genql/cli (npm) Jul 16, 2026
0x00-sys Credited to 0x00-sys
Laravel-Mediable: path traversal vulnerability in the File::sanitizePath() High
CVE-2026-49970 was published for plank/laravel-mediable (Composer) Jul 13, 2026
0x00-sys Credited to 0x00-sys
MLflow: trace API endpoints lack proper authorization validators High
CVE-2026-8147 was published for mlflow (pip) Jul 2, 2026
0x00-sys Credited to 0x00-sys
Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK High
CVE-2026-54428 was published for org.apache.httpcomponents.core5:httpcore5-h2 (Maven) Jul 1, 2026
Lueton Credited to Lueton
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation High
CVE-2026-53435 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
SVGO removeScripts plugin leaves some executable scripts intact High
CVE-2026-73650 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
ProTip! Advisories are also available from the GraphQL API