Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,054 advisories

Loading
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables High
CVE-2026-56740 was published for org.jline:jline-remote-telnet (Maven) Jun 18, 2026
sectroyer Credited to sectroyer, j-zygmunt, and dolores193 j-zygmunt j-zygmunt
dolores193 dolores193
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry High
CVE-2026-56741 was published for org.jline:jline-remote-telnet (Maven) Jun 18, 2026
sectroyer Credited to sectroyer, j-zygmunt, and dolores193 j-zygmunt j-zygmunt
dolores193 dolores193
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
CVE-2026-18401 was published for com.fasterxml.jackson.core:jackson-core (Maven) Feb 28, 2026
sprabhav7 Credited to sprabhav7, rohan-repos, neilmadden-hazelcast, awsactran, cowtowncoder, and anthonydahanne rohan-repos rohan-repos
neilmadden-hazelcast neilmadden-hazelcast awsactran awsactran cowtowncoder cowtowncoder anthonydahanne anthonydahanne
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-6qm2-mcq7-53qp was published for tools.jackson.core:jackson-core (Maven) Aug 4, 2026 withdrawn
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames Critical
CVE-2026-25534 was published for io.spinnaker.clouddriver:clouddriver-artifacts (Maven) Mar 16, 2026
jaydhulia Credited to jaydhulia, jasonmcintosh, and sealbenb jasonmcintosh jasonmcintosh
sealbenb sealbenb
OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE High
CVE-2026-22244 was published for org.open-metadata:platform (Maven) Jan 7, 2026
lnlinh31 Credited to lnlinh31, manerow, TeddyCr, pmbrull, and sealbenb manerow manerow
TeddyCr TeddyCr pmbrull pmbrull sealbenb sealbenb
hermes-management is vulnerable to RCE due to Apache commons-jxpath Critical
GHSA-2gh6-wc3m-g37f was published for pl.allegro.tech.hermes:hermes-management (Maven) Sep 17, 2024
sealbenb Credited to sealbenb
Apache Tomcat - Client certificate verification bypass Moderate
CVE-2025-66614 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Feb 17, 2026
Jenson3210 Credited to Jenson3210, yusuke-koyoshi, and sealbenb yusuke-koyoshi yusuke-koyoshi
sealbenb sealbenb
Apache Pinot Vulnerable to Authentication Bypass Critical
CVE-2024-56325 was published for org.apache.pinot:pinot-broker (Maven) Apr 1, 2025
AnonySE26 Credited to AnonySE26 and sealbenb sealbenb sealbenb
Apache Dolphinscheduler Code Injection vulnerability Critical
CVE-2024-43202 was published for org.apache.dolphinscheduler:dolphinscheduler-task-api (Maven) Aug 20, 2024
sealbenb Credited to sealbenb
Apache Polaris has an Improper Input Validation issue Critical
CVE-2026-42812 was published for org.apache.polaris:polaris-runtime-service (Maven) May 4, 2026
sealbenb Credited to sealbenb
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications Critical
CVE-2024-38821 was published for org.springframework.security:spring-security-web (Maven) Oct 28, 2024
sealbenb Credited to sealbenb
Apache Ranger UI vulnerable to Server Side Request Forgery Critical
CVE-2024-45479 was published for org.apache.ranger:ranger (Maven) Jan 22, 2025
sealbenb Credited to sealbenb
Apache Tomcat - HTTP/2 request headers not validated Critical
CVE-2026-41293 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 12, 2026
sealbenb Credited to sealbenb
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types High
CVE-2026-44795 was published for io.spinnaker.orca:orca-core (Maven) Jun 22, 2026
Freakston Credited to Freakston and connorshea connorshea connorshea
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass Critical
CVE-2026-18963 was published for org.keycloak:keycloak-services (Maven) Aug 18, 2026
madmuffin1 Credited to madmuffin1, greiffmode, and pv-rudger greiffmode greiffmode
pv-rudger pv-rudger
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context Moderate
CVE-2026-55858 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55857 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB has cleartext password disclosure to a MITM on the initial-handshake Moderate
CVE-2026-55856 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
MapFish Print has XXE that allows reading arbitrary files of certain types High
CVE-2026-55848 was published for org.mapfish.print:print-lib (Maven) Aug 28, 2026
zneek Credited to zneek
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens Moderate
CVE-2026-55867 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
michaelddickenson Credited to michaelddickenson and sreelim sreelim sreelim
Fortigate syslog message parser can be exploited to modify or delete fields from the original message High
CVE-2026-55841 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
joseluisgonzalezca Credited to joseluisgonzalezca and borjam borjam borjam
ProTip! Advisories are also available from the GraphQL API