Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,339 advisories

Loading
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables High
CVE-2026-56740 was published for org.jline:jline-remote-telnet (Maven) Jun 18, 2026
sectroyer Credited to sectroyer, j-zygmunt, and dolores193 j-zygmunt j-zygmunt
dolores193 dolores193
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry High
CVE-2026-56741 was published for org.jline:jline-remote-telnet (Maven) Jun 18, 2026
sectroyer Credited to sectroyer, j-zygmunt, and dolores193 j-zygmunt j-zygmunt
dolores193 dolores193
OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE High
CVE-2026-22244 was published for org.open-metadata:platform (Maven) Jan 7, 2026
lnlinh31 Credited to lnlinh31, manerow, TeddyCr, pmbrull, and sealbenb manerow manerow
TeddyCr TeddyCr pmbrull pmbrull sealbenb sealbenb
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types High
CVE-2026-44795 was published for io.spinnaker.orca:orca-core (Maven) Jun 22, 2026
Freakston Credited to Freakston and connorshea connorshea connorshea
MapFish Print has XXE that allows reading arbitrary files of certain types High
CVE-2026-55848 was published for org.mapfish.print:print-lib (Maven) Aug 28, 2026
zneek Credited to zneek
Fortigate syslog message parser can be exploited to modify or delete fields from the original message High
CVE-2026-55841 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
joseluisgonzalezca Credited to joseluisgonzalezca and borjam borjam borjam
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters High
CVE-2026-49042 was published for org.apache.camel:camel-langchain4j-agent (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
PowSyBl Core has Command Injection in LocalCommandExecutor-s High
CVE-2026-55673 was published for com.powsybl:powsybl-computation-local (Maven) Aug 28, 2026
Freakston Credited to Freakston
Spinnaker: Improper yaml processing on kustomize bake operations High
CVE-2026-55175 was published for io.spinnaker.rosco:rosco-manifests (Maven) Aug 28, 2026
thesecguy45 Credited to thesecguy45 and jasonmcintosh jasonmcintosh jasonmcintosh
Yamcs has Unauthenticated Directory Traversal High
CVE-2026-55552 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811, AbdrrahimDahmani, and 0x4ndy AbdrrahimDahmani AbdrrahimDahmani
0x4ndy 0x4ndy
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities High
CVE-2026-55521 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation High
CVE-2026-53435 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Apache Camel JMS deserialization filter bypass High
CVE-2026-43866 was published for org.apache.camel:camel-activemq (Maven) Jul 6, 2026
oscerd Credited to oscerd
ProTip! Advisories are also available from the GraphQL API