Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

461 advisories

Loading
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials High
GHSA-3f6p-5ww8-9rcr was published for mysql2 (npm) Sep 1, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` High
CVE-2026-55215 was published for mariadb (npm) Aug 28, 2026
gasbugs Credited to gasbugs
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url High
CVE-2026-67425 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted High
CVE-2026-67427 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
nebula-mesh: Operator session tokens stored in plaintext in the database High
CVE-2026-53603 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
ProTip! Advisories are also available from the GraphQL API