Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,430 advisories

Loading
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
Jenkins GitHub Plugin has an XSS vulnerability Critical
CVE-2026-42523 was published for com.coravy.hudson.plugins.github:github (Maven) Apr 29, 2026
sealbenb Credited to sealbenb
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest Critical
CVE-2026-42027 was published for org.apache.opennlp:opennlp-tools (Maven) May 4, 2026
sealbenb Credited to sealbenb and maheshwarivijaykumar maheshwarivijaykumar maheshwarivijaykumar
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets" High
CVE-2026-55153 was published for com.mchange:mchange-commons-java (Maven) Aug 14, 2026
4ra1n Credited to 4ra1n, unam4, and vmulas unam4 unam4
vmulas vmulas
OpenAM Insecure SSO Cookie Initialization High
CVE-2026-53660 was published for org.openidentityplatform.openam:openam-core (Maven) Aug 14, 2026
wodzen Credited to wodzen
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Grav: Unauthenticated denial of service via unbounded image derivative dimensions High
CVE-2026-53653 was published for getgrav/grav (Composer) Aug 14, 2026
iliaal Credited to iliaal
ldap3_proto has LDAP Filter stack exhaustion High
GHSA-qcxq-75wr-5cm8 was published for ldap3_proto (Rust) May 6, 2026
mbarbero Credited to mbarbero and micolous micolous micolous
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth and 36degrees 36degrees 36degrees
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution Critical
CVE-2026-53476 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication Critical
CVE-2026-53475 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands Critical
CVE-2026-53474 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist High
CVE-2026-35219 was published for @budibase/server (npm) Aug 14, 2026
Directus has a DOM-Based cross-site scripting (XSS) via layout_options Low
CVE-2024-6533 was published for directus (npm) Jan 23, 2025
Amayyas Credited to Amayyas
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL Moderate
CVE-2026-53722 was published for nuxt (npm) Jun 16, 2026
manop55555 Credited to manop55555, sota70, and sealonohana sota70 sota70
sealonohana sealonohana
alcls01111 Credited to alcls01111, cookesan, and sealonohana cookesan cookesan
sealonohana sealonohana
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing High
CVE-2026-2332 was published for org.eclipse.jetty:jetty-http (Maven) Apr 14, 2026
xclow3n Credited to xclow3n, jhy, tlarionova-max, and ryanmurf jhy jhy
tlarionova-max tlarionova-max ryanmurf ryanmurf
CakePHP Authentication: Open redirect weakness via backslash bypass Moderate
CVE-2026-55590 was published for cakephp/authentication (Composer) Jun 17, 2026
edorian Credited to edorian, markstory, and aquaturtlium markstory markstory
aquaturtlium aquaturtlium
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation Critical
CVE-2026-53471 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs Critical
CVE-2026-53470 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) High
CVE-2026-54513 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
fast-uri vulnerable to host confusion via failed IDN canonicalization High
CVE-2026-13676 was published for fast-uri (npm) Jul 21, 2026
celinke97 Credited to celinke97 and UlisesGascon UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API