Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,368 advisories

Loading
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification Moderate
GHSA-248h-974q-xrc2 was published for com.getaxonflow:axonflow-sdk (Maven) May 6, 2026
massif-01 Credited to massif-01
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
CVE-2026-18401 was published for com.fasterxml.jackson.core:jackson-core (Maven) Feb 28, 2026
sprabhav7 Credited to sprabhav7, rohan-repos, neilmadden-hazelcast, awsactran, cowtowncoder, and anthonydahanne rohan-repos rohan-repos
neilmadden-hazelcast neilmadden-hazelcast awsactran awsactran cowtowncoder cowtowncoder anthonydahanne anthonydahanne
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-6qm2-mcq7-53qp was published for tools.jackson.core:jackson-core (Maven) Aug 4, 2026 withdrawn
Apache Tomcat - Client certificate verification bypass Moderate
CVE-2025-66614 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Feb 17, 2026
Jenson3210 Credited to Jenson3210, yusuke-koyoshi, and sealbenb yusuke-koyoshi yusuke-koyoshi
sealbenb sealbenb
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context Moderate
CVE-2026-55858 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55857 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB has cleartext password disclosure to a MITM on the initial-handshake Moderate
CVE-2026-55856 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens Moderate
CVE-2026-55867 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
michaelddickenson Credited to michaelddickenson and sreelim sreelim sreelim
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter Moderate
CVE-2026-49099 was published for org.apache.camel:camel-salesforce (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter Moderate
CVE-2026-48206 was published for org.apache.camel:camel-jira (Maven) Jul 6, 2026
oscerd Credited to oscerd
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields Moderate
CVE-2026-55425 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
Evelynkaz Credited to Evelynkaz
Yamcs has DOM XSS in Extension Routing Moderate
CVE-2026-55566 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811
Yamcs has Reflected XSS in the URL of the Authorize Endpoint Moderate
CVE-2026-55549 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811, AbdrrahimDahmani, and 0x4ndy AbdrrahimDahmani AbdrrahimDahmani
0x4ndy 0x4ndy
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets Moderate
CVE-2026-55548 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
lucquach Credited to lucquach
de3erve Credited to de3erve
ProTip! Advisories are also available from the GraphQL API