Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

409 advisories

Loading
oscerd Credited to oscerd
Spring Web Services: WSS4J validation does not use configured replay cache Low
CVE-2026-41000 was published for org.springframework.ws:spring-ws-security (Maven) Jun 11, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max Low
CVE-2026-61634 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
Alexender676 Credited to Alexender676
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads Low
CVE-2026-41694 was published for org.springframework.security:spring-security-saml2-service-provider (Maven) Jun 10, 2026
Spring Framework Denial of Service via AntPathMatcher Low
CVE-2026-41848 was published for org.springframework:spring-core (Maven) Jun 9, 2026
Spring Framework Arbitrary Method Invocation in SpEL Expressions Low
CVE-2026-41852 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
hsweb-framework has a Path Traversal issue Low
CVE-2026-11470 was published for org.hswebframework.web:hsweb-system-file (Maven) Jun 8, 2026
hsweb-framework has an open redirect issue Low
CVE-2026-11477 was published for org.hswebframework.web:hsweb-authorization-oauth2 (Maven) Jun 8, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
Keycloak: Information disclosure due to user profile permission bypass Low
CVE-2026-9088 was published for org.keycloak:keycloak-services (Maven) Jun 5, 2026
Logback vulnerable to Object Injection through HardenedObjectInputStream modules Low
CVE-2026-10532 was published for ch.qos.logback:logback-core (Maven) Jun 1, 2026
lgf10 Credited to lgf10
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation Low
CVE-2026-4874 was published for org.keycloak:keycloak-services (Maven) Mar 26, 2026
krapovneru Credited to krapovneru, dnegreira, and ahus1 dnegreira dnegreira
ahus1 ahus1
Keycloak vulnerable to information disclosure via CORS header injection due to unvalidated JWT azp claim Low
CVE-2026-37977 was published for org.keycloak:keycloak-services (Maven) Apr 6, 2026
ahus1 Credited to ahus1
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login Low
CVE-2026-48589 was published for org.apache.shiro:shiro-jakarta-ee (Maven) May 26, 2026
yeikel Credited to yeikel
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. Low
CVE-2026-22741 was published for org.springframework:spring-webflux (Maven) Apr 29, 2026
yuki-matsuhashi Credited to yuki-matsuhashi
QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability Low
CVE-2026-9828 was published for ch.qos.logback:logback-core (Maven) May 28, 2026
tonghuaroot Credited to tonghuaroot and jonesbusy jonesbusy jonesbusy
CrateDB's Blob HTTP handler bypasses authorization Low
CVE-2026-49989 was published for io.crate:crate (Maven) Jul 1, 2026
fab1ano Credited to fab1ano and matriv matriv matriv
offset Credited to offset, jojojo8359, and smallex jojojo8359 jojojo8359
smallex smallex
Sigstore Java has a vulnerability with bundle verification of integratedTime Low
CVE-2026-48791 was published for dev.sigstore:sigstore-java (Maven) Jun 30, 2026
TCC-TRANSACTION has an Improper Input Validation vulnerability Low
CVE-2026-9497 was published for org.mengyun:tcc-transaction (Maven) May 26, 2026
jasypt-spring-boot Uses a One-Way Hash without a Salt Low
CVE-2026-9370 was published for com.github.ulisesbocchio:jasypt-spring-boot (Maven) May 26, 2026
Apache Tomcat - Security constraint bypass with HTTP/0.9 Low
CVE-2026-24733 was published for org.apache.tomcat:tomcat-coyote (Maven) Feb 17, 2026
Jenson3210 Credited to Jenson3210 and yusuke-koyoshi yusuke-koyoshi yusuke-koyoshi
OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget` Low
CVE-2026-44793 was published for org.openidentityplatform.openam:openam-federation-library (Maven) Jun 22, 2026
gujjuboy10x00 Credited to gujjuboy10x00
Keycloak's identity-first login flow exposes user information Low
CVE-2026-4633 was published for org.keycloak:keycloak-services (Maven) Mar 23, 2026
dnegreira Credited to dnegreira and julianladisch julianladisch julianladisch
ProTip! Advisories are also available from the GraphQL API