Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

462 advisories

Loading
sondt99 Credited to sondt99
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Electron: Cross-origin iframe can position native autofill popup Low
CVE-2026-70600 was published for electron (npm) Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size Low
CVE-2026-70598 was published for electron (npm) Aug 5, 2026
@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header Low
CVE-2026-53607 was published for apostrophe (npm) Jul 31, 2026
EchoSkorJjj Credited to EchoSkorJjj
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate Low
GHSA-pc2w-4mq8-32qw was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 29, 2026
yotampe-pluto Credited to yotampe-pluto
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
sec-reex Credited to sec-reex and LlewxamDev LlewxamDev LlewxamDev
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ Low
CVE-2026-54335 was published for @feathersjs/commons (npm) Jul 14, 2026
ridingsa Credited to ridingsa
Waku has an Open Redirect via `unstable_redirect` Helper Low
CVE-2026-49456 was published for waku (npm) Jul 8, 2026
j0hndo Credited to j0hndo
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows Low
GHSA-2vg6-77g8-24mp was published for @better-auth/scim (npm) Jul 7, 2026
iruizsalinas Credited to iruizsalinas
OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement Low
GHSA-3wqp-prf6-2m72 was published for openclaw (npm) Jul 2, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url Low
GHSA-rp72-5v5q-2446 was published for @cardano402/mcp-server (npm) Jun 26, 2026
MorganOnCode Credited to MorganOnCode
neotoma has tenant isolation gap in relationship query endpoints Low
GHSA-wrr4-782v-jhwh was published for neotoma (npm) Jun 25, 2026
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change Low
GHSA-97pr-9hgg-3p8r was published for parse-server (npm) Jun 19, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe Low
GHSA-h5jc-78hr-3pc9 was published for @sveltia/cms (npm) Jun 19, 2026
blacksolo1 Credited to blacksolo1
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist Low
CVE-2026-55778 was published for parse-server (npm) Jun 19, 2026
mtrezza Credited to mtrezza
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist Low
CVE-2026-53724 was published for parse-server (npm) Jun 19, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
sondt99 Credited to sondt99
UlisesGascon Credited to UlisesGascon, KhafraDev, and mcollina KhafraDev KhafraDev
mcollina mcollina
ProTip! Advisories are also available from the GraphQL API