Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

193 advisories

Loading
MeshCentral has unsanitized data fields High
GHSA-c7hr-448w-65px was published for meshcentral (npm) Aug 18, 2026
kevthehermit Credited to kevthehermit
manus-use Credited to manus-use
hashi-vault-js has a path traversal and query parameter injection High
CVE-2026-55100 was published for hashi-vault-js (npm) Jul 31, 2026
Sebasteuo Credited to Sebasteuo
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template High
CVE-2026-54661 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template High
CVE-2026-54662 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output High
CVE-2026-55404 was published for yt-dlp (pip) Jul 24, 2026
gamer191 Credited to gamer191 and bashonly bashonly bashonly
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) High
GHSA-3rp5-jjmw-4wv2 was published for gitpython (pip) Jul 24, 2026
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js High
GHSA-vwjc-v7x7-cm6g was published for com.arcadedb:arcadedb-engine (Maven) Jul 16, 2026
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services High
GHSA-pqg7-v6wh-3pfp was published for github.com/almeidapaulopt/tsdproxy (Go) Jul 14, 2026
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` High
CVE-2026-55427 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Langroid: handle_message() executes user-supplied tool JSON without sender verification High
CVE-2026-54771 was published for langroid (pip) Jul 6, 2026
u-ktdi Credited to u-ktdi
Flawfinder output manipulation via untrusted filenames and source text High
CVE-2026-48813 was published for flawfinder (pip) Jun 26, 2026
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection High
CVE-2026-54329 was published for snipe/snipe-it (Composer) Jun 23, 2026
tahirsercan Credited to tahirsercan
OpenAM has LDAP Injection via `_queryId` Parameter High
CVE-2026-41573 was published for org.openidentityplatform.openam:openam-core-rest (Maven) Jun 22, 2026
nn0nkey Credited to nn0nkey
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull High
CVE-2026-53488 was published for github.com/containerd/containerd (Go) Jun 19, 2026
robertprast Credited to robertprast
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode High
CVE-2026-57209 was published for github.com/dadrus/heimdall (Go) Jun 18, 2026
tikket1 Credited to tikket1
yt-dlp: Arbitrary code execution via manifest downloads with aria2c High
CVE-2026-50574 was published for yt-dlp (pip) Jun 16, 2026
seproDev Credited to seproDev, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection High
CVE-2025-27511 was published for org.geoserver.extension:gs-db2 (Maven) Jun 11, 2026
H4cking2theGate Credited to H4cking2theGate, jodygarnett, and aaime jodygarnett jodygarnett
aaime aaime
Froxlor: BIND Zone File Injection via TXT Record Content High
CVE-2026-41234 was published for froxlor/froxlor (Composer) Jun 3, 2026
hett-patell Credited to hett-patell and SKaif009 SKaif009 SKaif009
Froxlor has an incomplete fix for CVE-2026-30932 High
CVE-2026-41237 was published for froxlor/froxlor (Composer) May 29, 2026
decsecre583 Credited to decsecre583
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection High
CVE-2026-42334 was published for mongoose (npm) May 5, 2026
cataliniovita-snyk Credited to cataliniovita-snyk and katzj katzj katzj
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters High
GHSA-27qh-8cxx-2cr5 was published for aws/aws-sdk-php (Composer) Mar 27, 2026
ProTip! Advisories are also available from the GraphQL API