Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13 advisories

Loading
Pig-Tail Credited to Pig-Tail
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding High
CVE-2026-63202 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
Pig-Tail Credited to Pig-Tail
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries Moderate
CVE-2026-64662 was published for statamic/cms (Composer) Aug 6, 2026
Pig-Tail Credited to Pig-Tail and luuhung1217 luuhung1217 luuhung1217
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Moderate
CVE-2026-54764 was published for github.com/traefik/traefik (Go) Aug 6, 2026
Pig-Tail Credited to Pig-Tail
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect Moderate
CVE-2026-67435 was published for linuxfabrik-lib (pip) Jul 30, 2026
Pig-Tail Credited to Pig-Tail
anir0y Credited to anir0y, manus-use, sermikr0, adamyordan, Pig-Tail, tonghuaroot, and alimony manus-use manus-use
sermikr0 sermikr0 adamyordan adamyordan Pig-Tail Pig-Tail tonghuaroot tonghuaroot alimony alimony
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass Critical
CVE-2026-62263 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jul 24, 2026
Pig-Tail Credited to Pig-Tail, MarkLee131, baradika, manus-use, and tonghuaroot MarkLee131 MarkLee131
baradika baradika manus-use manus-use tonghuaroot tonghuaroot
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints Moderate
CVE-2026-14620 was published for webpack-dev-server (npm) Jul 20, 2026
Pig-Tail Credited to Pig-Tail, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
nebula-mesh: Certificate revocation is never enforced at the mesh High
CVE-2026-61699 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
Pig-Tail Credited to Pig-Tail
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch Moderate
GHSA-h5rg-8p7f-47g2 was published for surrealdb (Rust) Jun 19, 2026
Pig-Tail Credited to Pig-Tail
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing Moderate
CVE-2026-54697 was published for org.connectbot.sshlib:sshlib (Maven) Jun 12, 2026
Pig-Tail Credited to Pig-Tail and kruton kruton kruton
ProTip! Advisories are also available from the GraphQL API