Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,589 advisories

Loading
Filament: Password validity disclosure for accounts denied panel access on login page Low
CVE-2026-84307 was published for filament/filament (Composer) Sep 1, 2026
danharrin Credited to danharrin
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter Low
CVE-2026-42350 was published for github.com/akuity/kargo (Go) Aug 27, 2026
PontusHanssen Credited to PontusHanssen, krancour, and rpelczar krancour krancour
rpelczar rpelczar
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Low
CVE-2026-54713 was published for cakephp/queue (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
kas Persistently Disables SSH Host Key Checking Low
CVE-2026-54548 was published for kas (pip) Aug 26, 2026
shubtheone Credited to shubtheone
netfoil vulnerable to improper handling of untrusted DoH response data Low
GHSA-4ph6-mjv7-3fq6 was published for github.com/tinfoil-factory/netfoil (Go) Aug 24, 2026
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints Low
GHSA-rxhg-vcww-2mpw was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
axel-corsiez Credited to axel-corsiez
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings Low
GHSA-h58c-xccx-75m3 was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison Low
GHSA-8fxq-53rx-ph5f was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing Low
CVE-2026-61712 was published for github.com/moby/buildkit (Go) Aug 19, 2026
MobSF has SSRF port restriction bypass in assetlinks_check Low
CVE-2026-68927 was published for mobsf (pip) Aug 18, 2026
DavidCarliez Credited to DavidCarliez
sondt99 Credited to sondt99
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max Low
CVE-2026-61634 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
Alexender676 Credited to Alexender676
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
CVE-2026-72783 was published for craftcms/cms (Composer) Aug 6, 2026
ProTip! Advisories are also available from the GraphQL API