Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets Moderate
CVE-2026-63179 was published for winter/wn-backend-module (Composer) Aug 20, 2026
hypnguyen1209 Credited to hypnguyen1209
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs High
CVE-2026-70666 was published for lemur (pip) Aug 18, 2026
hypnguyen1209 Credited to hypnguyen1209
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
CVE-2026-73644 was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
ProTip! Advisories are also available from the GraphQL API