Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

491 advisories

Loading
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
aiosmtplib: STARTTLS response injection Moderate
CVE-2026-55558 was published for aiosmtplib (pip) Aug 27, 2026
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings Low
GHSA-h58c-xccx-75m3 was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields Moderate
CVE-2026-54543 was published for froxlor/froxlor (Composer) Aug 18, 2026
YHalo-wyh Credited to YHalo-wyh
MeshCentral has unsanitized data fields High
GHSA-c7hr-448w-65px was published for meshcentral (npm) Aug 18, 2026
kevthehermit Credited to kevthehermit
manus-use Credited to manus-use
Zelys-DFKH Credited to Zelys-DFKH, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
hashi-vault-js has a path traversal and query parameter injection High
CVE-2026-55100 was published for hashi-vault-js (npm) Jul 31, 2026
Sebasteuo Credited to Sebasteuo
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template High
CVE-2026-54661 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template High
CVE-2026-54662 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output High
CVE-2026-55404 was published for yt-dlp (pip) Jul 24, 2026
gamer191 Credited to gamer191 and bashonly bashonly bashonly
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) High
GHSA-3rp5-jjmw-4wv2 was published for gitpython (pip) Jul 24, 2026
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code Low
GHSA-rjwr-m7qx-3fjr was published for github.com/oapi-codegen/oapi-codegen/v2 (Go) Jul 17, 2026
quart27219 Credited to quart27219 and kimdu0 kimdu0 kimdu0
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js High
GHSA-vwjc-v7x7-cm6g was published for com.arcadedb:arcadedb-engine (Maven) Jul 16, 2026
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services High
GHSA-pqg7-v6wh-3pfp was published for github.com/almeidapaulopt/tsdproxy (Go) Jul 14, 2026
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE Critical
CVE-2026-54159 was published for prestashop/ps_facetedsearch (Composer) Jul 10, 2026
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping Moderate
CVE-2026-53572 was published for github.com/kedacore/keda/v2 (Go) Jul 7, 2026
mert2m Credited to mert2m
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` High
CVE-2026-55427 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Langroid: handle_message() executes user-supplied tool JSON without sender verification High
CVE-2026-54771 was published for langroid (pip) Jul 6, 2026
u-ktdi Credited to u-ktdi
WeasyPrint has CSS Injection via Presentational Hints Moderate
CVE-2026-49452 was published for weasyprint (pip) Jul 6, 2026
AyushParkara Credited to AyushParkara
ProTip! Advisories are also available from the GraphQL API