Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,339 advisories

Loading
MapFish Print has XXE that allows reading arbitrary files of certain types High
CVE-2026-55848 was published for org.mapfish.print:print-lib (Maven) Aug 28, 2026
zneek Credited to zneek
Fortigate syslog message parser can be exploited to modify or delete fields from the original message High
CVE-2026-55841 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
joseluisgonzalezca Credited to joseluisgonzalezca and borjam borjam borjam
PowSyBl Core has Command Injection in LocalCommandExecutor-s High
CVE-2026-55673 was published for com.powsybl:powsybl-computation-local (Maven) Aug 28, 2026
Freakston Credited to Freakston
Spinnaker: Improper yaml processing on kustomize bake operations High
CVE-2026-55175 was published for io.spinnaker.rosco:rosco-manifests (Maven) Aug 28, 2026
thesecguy45 Credited to thesecguy45 and jasonmcintosh jasonmcintosh jasonmcintosh
Yamcs has Unauthenticated Directory Traversal High
CVE-2026-55552 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811, AbdrrahimDahmani, and 0x4ndy AbdrrahimDahmani AbdrrahimDahmani
0x4ndy 0x4ndy
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities High
CVE-2026-55521 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries High
CVE-2026-54550 was published for org.codehaus.izpack:izpack-installer (Maven) Aug 26, 2026
sectroyer Credited to sectroyer
http4s has HTTP/2 Denial of Service with Ember Backend High
CVE-2026-54556 was published for org.http4s:http4s-ember-core_2.12 (Maven) Aug 26, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
Sakai Conversations has a Stored XSS Issue High
CVE-2026-54049 was published for org.sakaiproject.conversations:sakai-conversations-impl (Maven) Aug 24, 2026
geo-chen Credited to geo-chen and ottenhoff ottenhoff ottenhoff
oscerd Credited to oscerd
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding High
CVE-2026-63202 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
Pig-Tail Credited to Pig-Tail
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields High
CVE-2026-61827 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary High
CVE-2026-63124 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99 and VuiVeIshere VuiVeIshere VuiVeIshere
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages High
CVE-2026-61798 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (Maven) Aug 20, 2026
sondt99 Credited to sondt99
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service High
CVE-2026-54251 was published for io.netty.incubator:netty-incubator-codec-ohttp (Maven) Aug 20, 2026
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates High
CVE-2024-45747 was published for org.geoserver.web:gs-web-app (Maven) Aug 19, 2026
mbadanoiu Credited to mbadanoiu and sikeoka sikeoka sikeoka
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing High
CVE-2026-53966 was published for org.xwiki.platform:xwiki-platform-livedata-livetable (Maven) Aug 19, 2026
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading High
CVE-2026-63337 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation High
CVE-2026-69219 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS High
CVE-2026-69220 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection High
CVE-2026-55839 was published for io.kestra:kestra (Maven) Aug 18, 2026
5h1kh4r Credited to 5h1kh4r
http4k: `DigestAuthProvider.verify` did not bind to request URI High
CVE-2026-54148 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
ProTip! Advisories are also available from the GraphQL API