Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,479 advisories

Loading
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike High
CVE-2026-47683 was published for vm2 (npm) Aug 17, 2026
fg0x0 Credited to fg0x0 and Kr1shna4garwal Kr1shna4garwal Kr1shna4garwal
sqlparse: Quadratic O(n²) DoS in group_comments High
CVE-2026-71491 was published for sqlparse (pip) Aug 17, 2026
sanktjodel Credited to sanktjodel and mohammedix88 mohammedix88 mohammedix88
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config Moderate
CVE-2026-68520 was published for glances (pip) Aug 17, 2026
0xTodor Credited to 0xTodor
sec-reex Credited to sec-reex
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes Moderate
CVE-2026-59894 was published for sqlparse (pip) Aug 17, 2026
7thParkk Credited to 7thParkk
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest Moderate
CVE-2026-45099 was published for github.com/gruntwork-io/terragrunt (Go) Aug 17, 2026
tonghuaroot Credited to tonghuaroot
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass Moderate
CVE-2026-64865 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388
New API: Integer overflow in quota billing yields negative charges (self-crediting) Critical
CVE-2026-71479 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388 and Calcium-Ion Calcium-Ion Calcium-Ion
New API: Admin can reset passkeys for same-level or higher-privileged users Moderate
CVE-2026-64866 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
Mi0uno Credited to Mi0uno
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging High
CVE-2026-64868 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
passer12 Credited to passer12
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation Critical
CVE-2026-64859 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
August829 Credited to August829
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage High
CVE-2026-53728 was published for @medplum/core (npm) Aug 17, 2026
sAjibuu Credited to sAjibuu
conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target Critical
CVE-2026-55158 was published for wktk/conflibot (GitHub Actions) Aug 17, 2026
DeepmergeTS has stack exhaustion when merging recursive object graphs High
CVE-2026-40345 was published for deepmerge-ts (npm) Aug 17, 2026
Jvr2022 Credited to Jvr2022
s2n-quic has excessive memory allocation Moderate
CVE-2026-10740 was published for s2n-quic (Rust) Aug 14, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints Moderate
CVE-2026-55156 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
232-323 Credited to 232-323
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info High
CVE-2026-55157 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
mcfly-zzh Credited to mcfly-zzh
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets" High
CVE-2026-55153 was published for com.mchange:mchange-commons-java (Maven) Aug 14, 2026
4ra1n Credited to 4ra1n, unam4, and vmulas unam4 unam4
vmulas vmulas
OpenAM Insecure SSO Cookie Initialization High
CVE-2026-53660 was published for org.openidentityplatform.openam:openam-core (Maven) Aug 14, 2026
wodzen Credited to wodzen
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
ProTip! Advisories are also available from the GraphQL API