Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,430 advisories

Loading
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect Moderate
GHSA-h4mf-4v27-hggj was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys Moderate
GHSA-8mxv-9xhp-86h4 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering Moderate
CVE-2026-71293 was published for statamic/cms (Composer) Aug 5, 2026
Wings exposes node configuration secrets through egg configuration-file templating Critical
CVE-2026-52855 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
robertdrakedennis Credited to robertdrakedennis
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url High
CVE-2026-67425 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted High
CVE-2026-67427 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
ProTip! Advisories are also available from the GraphQL API