Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,479 advisories

Loading
geo-chen Credited to geo-chen
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth Moderate
CVE-2026-69146 was published for mlflow (npm) Aug 17, 2026
geo-chen Credited to geo-chen
freeman-bb Credited to freeman-bb, y011d4, ibondarenko1, h1-mrz, and th3cyb3rc0p y011d4 y011d4
ibondarenko1 ibondarenko1 h1-mrz h1-mrz th3cyb3rc0p th3cyb3rc0p
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint High
CVE-2026-56677 was published for 9router (npm) Aug 17, 2026
HK4zCzi Credited to HK4zCzi
http4k: `DigestAuthProvider.verify` did not bind to request URI High
CVE-2026-54148 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI Moderate
CVE-2026-54147 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots Moderate
CVE-2026-53766 was published for chrome-devtools-mcp (npm) Aug 17, 2026
enable7997 Credited to enable7997
package pkcs12: Authentication bypass in Decode functions Moderate
GHSA-mpwr-8vm7-h73f was published for software.sslmate.com/src/go-pkcs12 (Go) Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE) High
GHSA-xhcr-cqfr-m3hv was published for atomic-agents-stack (pip) Aug 17, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite Moderate
CVE-2026-59903 was published for io.netty:netty-codec-http (Maven) Aug 17, 2026
violetagg Credited to violetagg
Netty: Memory Exhaustion in SctpMessageCompletionHandler High
CVE-2026-59902 was published for io.netty:netty-transport-sctp (Maven) Aug 17, 2026
violetagg Credited to violetagg
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set High
GHSA-fhgh-wq4q-r37x was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
arpitjain099 Credited to arpitjain099
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
tonghuaroot Credited to tonghuaroot
Etherpad has stored XSS in HTML export via unescaped attribute-pool values High
CVE-2026-55090 was published for ep_etherpad-lite (npm) Aug 17, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability Moderate
CVE-2026-55062 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
uniget CLI has an EDITOR Command Injection Moderate
CVE-2026-55061 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass High
GHSA-v836-6xw4-9cx3 was published for vm2 (npm) Aug 17, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE Critical
CVE-2026-47686 was published for vm2 (npm) Aug 17, 2026
VladimirEliTokarev Credited to VladimirEliTokarev
ProTip! Advisories are also available from the GraphQL API