Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,587 advisories

Loading
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter Low
CVE-2026-42350 was published for github.com/akuity/kargo (Go) Aug 27, 2026
PontusHanssen Credited to PontusHanssen, krancour, and rpelczar krancour krancour
rpelczar rpelczar
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Low
CVE-2026-54713 was published for cakephp/queue (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
netfoil vulnerable to improper handling of untrusted DoH response data Low
GHSA-4ph6-mjv7-3fq6 was published for github.com/tinfoil-factory/netfoil (Go) Aug 24, 2026
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints Low
GHSA-rxhg-vcww-2mpw was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
axel-corsiez Credited to axel-corsiez
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings Low
GHSA-h58c-xccx-75m3 was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison Low
GHSA-8fxq-53rx-ph5f was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing Low
CVE-2026-61712 was published for github.com/moby/buildkit (Go) Aug 19, 2026
MobSF has SSRF port restriction bypass in assetlinks_check Low
CVE-2026-68927 was published for mobsf (pip) Aug 18, 2026
DavidCarliez Credited to DavidCarliez
sondt99 Credited to sondt99
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max Low
CVE-2026-61634 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
Alexender676 Credited to Alexender676
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
GHSA-7hxc-f267-h5q7 was published for craftcms/cms (Composer) Aug 6, 2026
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
ProTip! Advisories are also available from the GraphQL API