Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch Moderate
GHSA-h5rg-8p7f-47g2 was published for surrealdb (Rust) Jun 19, 2026
Pig-Tail Credited to Pig-Tail
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing Moderate
CVE-2026-54697 was published for org.connectbot.sshlib:sshlib (Maven) Jun 12, 2026
Pig-Tail Credited to Pig-Tail and kruton kruton kruton
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints Moderate
CVE-2026-14620 was published for webpack-dev-server (npm) Jul 20, 2026
Pig-Tail Credited to Pig-Tail, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect Moderate
CVE-2026-67435 was published for linuxfabrik-lib (pip) Jul 30, 2026
Pig-Tail Credited to Pig-Tail
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Moderate
CVE-2026-54764 was published for github.com/traefik/traefik (Go) Aug 6, 2026
Pig-Tail Credited to Pig-Tail
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries Moderate
CVE-2026-64662 was published for statamic/cms (Composer) Aug 6, 2026
Pig-Tail Credited to Pig-Tail and luuhung1217 luuhung1217 luuhung1217
ProTip! Advisories are also available from the GraphQL API