Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,978 advisories

Loading
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
GHSA-q53c-4prm-w95q was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
GHSA-w4hw-qcx7-56pr was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Path disclosure on Unix with Zsh Moderate
GHSA-6v4m-fw66-8r4x was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure High
CVE-2026-16584 was published for awslabs.aws-api-mcp-server (pip) Jul 24, 2026
arnewouters Credited to arnewouters
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
GHSA-86cx-wwf4-phq4 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
GHSA-95cv-r8x4-vh75 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
GHSA-7ppr-r889-mcf2 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) High
GHSA-46q4-43ph-c6fr was published for org.http4s:blaze-http_2.12 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser High
GHSA-mhvj-jhpq-885v was published for org.http4s:blaze-http_2.13 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover High
GHSA-cmwh-g2h8-c222 was published for poweradmin/poweradmin (Composer) Jul 24, 2026
William957-web Credited to William957-web
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account High
GHSA-h4hf-v6w5-897x was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password Critical
GHSA-f25v-x6vr-962g was published for pheditor/pheditor (Composer) Jul 24, 2026
sermikr0 Credited to sermikr0
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr
swift-nio-http2: Missing CR/LF/NUL validation in header values Moderate
CVE-2026-64785 was published for swift-nio-http2 (Swift) Jul 24, 2026
sour-exploit Credited to sour-exploit
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
GHSA-vh45-f885-3848 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review High
GHSA-47w6-gwp4-w6vc was published for vantage6 (pip) Jul 24, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics Low
GHSA-2625-rw7m-5q5x was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
GHSA-26gq-p25f-99cp was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
GHSA-g5vv-q72c-7j78 was published for @anephenix/hub (npm) Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources Moderate
GHSA-c534-2w9c-x7fm was published for github.com/zxh326/kite (Go) Jul 24, 2026
ProTip! Advisories are also available from the GraphQL API