Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,978 advisories

Loading
nono-cli'scregistry pack verification can fail open when provenance metadata is absent Moderate
GHSA-hc4m-q9jh-xw4j was published for nono-cli (Rust) Jul 28, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
b-hermes Credited to b-hermes
0x7d8 Credited to 0x7d8
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities High
CVE-2026-55771 was published for com.cedarpolicy:cedar-java (Maven) Jul 28, 2026
@wakaru/cli arbitrary file write during bundle unpack High
CVE-2026-54545 was published for @wakaru/cli (npm) Jul 28, 2026
j4k0xb Credited to j4k0xb
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler High
CVE-2026-47427 was published for github.com/github/github-mcp-server (Go) Jul 28, 2026
manthanghasadiya Credited to manthanghasadiya
lettre has TLS hostname verification disabled when using Boring TLS backend Critical
CVE-2026-46428 was published for lettre (Rust) Jul 28, 2026
edevil Credited to edevil
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC and rodrigoprimo rodrigoprimo rodrigoprimo
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
kodareef5 Credited to kodareef5
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages Moderate
CVE-2023-37465 was published for org.xwiki.contrib:discussions-server (Maven) Jul 27, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
GHSA-6vch-q96h-7gc3 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller Moderate
GHSA-8q49-2h5h-434x was published for @frontmcp/adapters (npm) Jul 24, 2026
EchoSkorJjj Credited to EchoSkorJjj and frontegg-david frontegg-david frontegg-david
matiasinsaurralde Credited to matiasinsaurralde
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages() High
CVE-2026-16796 was published for bedrock-agentcore (pip) Jul 24, 2026
MrCloudSec Credited to MrCloudSec
etcd: Watch API authorization bypass via open-ended range requests High
GHSA-xg4h-6gfc-h4m8 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
libp2p: yamux connection DoS via oversized data frame High
GHSA-hmj8-5xmh-5573 was published for libp2p (pip) Jul 24, 2026
tahaafarooq Credited to tahaafarooq
Quasar: Prototype pollution in the extend() utility Moderate
GHSA-3r53-75j5-3g7j was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
Oh My Posh: Arbitrary command execution via template injection in the path segment High
GHSA-6xj8-qv9j-xcjq was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data Moderate
GHSA-fwjx-9p69-h25h was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
ProTip! Advisories are also available from the GraphQL API