Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,612 advisories

Loading
SAP Approuter Vulnerable to HTTP Request Smuggling Critical
CVE-2026-27690 was published for @sap/approuter (npm) Jul 14, 2026
henrybrink Credited to henrybrink
Duplicate Advisory: Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element Critical
GHSA-4hc4-qjfx-wjf3 was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
arpitjain099 Credited to arpitjain099
Duplicate Advisory: better-auth has an external request basePath modification DoS Critical
GHSA-3q45-2fh7-66cj was published for better-auth (npm) Aug 2, 2026 withdrawn
antonisloukis Credited to antonisloukis
Gitea pre-receive hook scanner errors allow branch-protection bypass Critical
CVE-2026-27780 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry Critical
CVE-2026-26232 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass Critical
CVE-2026-26247 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections Critical
CVE-2026-26292 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths Critical
CVE-2026-25718 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields Critical
CVE-2026-22547 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames Critical
CVE-2026-25534 was published for io.spinnaker.clouddriver:clouddriver-artifacts (Maven) Mar 16, 2026
jaydhulia Credited to jaydhulia, jasonmcintosh, and sealbenb jasonmcintosh jasonmcintosh
sealbenb sealbenb
vLLM: OpenAI auth bypass Critical
CVE-2026-48746 was published for vllm (pip) Jun 16, 2026
x41j Credited to x41j, russellb, and DarkLight1337 russellb russellb
DarkLight1337 DarkLight1337
hermes-management is vulnerable to RCE due to Apache commons-jxpath Critical
GHSA-2gh6-wc3m-g37f was published for pl.allegro.tech.hermes:hermes-management (Maven) Sep 17, 2024
sealbenb Credited to sealbenb
Apache Pinot Vulnerable to Authentication Bypass Critical
CVE-2024-56325 was published for org.apache.pinot:pinot-broker (Maven) Apr 1, 2025
AnonySE26 Credited to AnonySE26 and sealbenb sealbenb sealbenb
Apache Dolphinscheduler Code Injection vulnerability Critical
CVE-2024-43202 was published for org.apache.dolphinscheduler:dolphinscheduler-task-api (Maven) Aug 20, 2024
sealbenb Credited to sealbenb
Apache Polaris has an Improper Input Validation issue Critical
CVE-2026-42812 was published for org.apache.polaris:polaris-runtime-service (Maven) May 4, 2026
sealbenb Credited to sealbenb
dash-uploader has a directory traversal vulnerability Critical
CVE-2026-38360 was published for dash-uploader (pip) May 8, 2026
a1ohadance Credited to a1ohadance
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications Critical
CVE-2024-38821 was published for org.springframework.security:spring-security-web (Maven) Oct 28, 2024
sealbenb Credited to sealbenb
Apache Ranger UI vulnerable to Server Side Request Forgery Critical
CVE-2024-45479 was published for org.apache.ranger:ranger (Maven) Jan 22, 2025
sealbenb Credited to sealbenb
Snowflake Connector for Python improperly verifies TLS hostnames Critical
CVE-2026-15925 was published for snowflake-connector-python (pip) Jul 16, 2026
Apache Tomcat - HTTP/2 request headers not validated Critical
CVE-2026-41293 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 12, 2026
sealbenb Credited to sealbenb
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, PowerliftLog, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren PowerliftLog PowerliftLog zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass Critical
CVE-2026-18963 was published for org.keycloak:keycloak-services (Maven) Aug 18, 2026
madmuffin1 Credited to madmuffin1, greiffmode, and pv-rudger greiffmode greiffmode
pv-rudger pv-rudger
ProTip! Advisories are also available from the GraphQL API