Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12 advisories

Loading
Russh: Channel-scoped server callbacks can be reached without an open channel Moderate
CVE-2026-68930 was published for russh (Rust) Aug 3, 2026
thesmartshadow Credited to thesmartshadow
hono/jsx does not isolate context per request, leading to cross-request data disclosure Moderate
CVE-2026-59896 was published for hono (npm) Jul 21, 2026
thesmartshadow Credited to thesmartshadow
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning High
CVE-2026-67320 was published for axios (npm) Jul 20, 2026
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification High
CVE-2026-32936 was published for github.com/coredns/coredns (Go) Apr 28, 2026
thesmartshadow Credited to thesmartshadow
thesmartshadow Credited to thesmartshadow
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion High
CVE-2026-34601 was published for @xmldom/xmldom (npm) Apr 1, 2026
thesmartshadow Credited to thesmartshadow and karfau karfau karfau
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href Moderate
CVE-2026-25500 was published for rack (RubyGems) Feb 17, 2026
thesmartshadow Credited to thesmartshadow, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
ProTip! Advisories are also available from the GraphQL API