Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,875 advisories

Loading
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Moderate
CVE-2026-54704 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
FWinkler79 Credited to FWinkler79
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion Moderate
CVE-2026-54712 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
decsecre583 Credited to decsecre583
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
veraPDF Parser DoS via PostScript Type 1 Font Programs Moderate
CVE-2026-54081 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Parser DoS via PostScript CMap Streams Moderate
CVE-2026-54080 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs Moderate
CVE-2026-54082 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
acornall Credited to acornall
veraPDF Validation XXE via Rich Text High
CVE-2026-54078 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Validation XXE via XFA High
CVE-2026-54079 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
wodzen Credited to wodzen
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities High
CVE-2026-55771 was published for com.cedarpolicy:cedar-java (Maven) Jul 28, 2026
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor High
CVE-2026-43910 was published for io.appium:java-client (Maven) Jul 28, 2026
RobertoLuzanilla Credited to RobertoLuzanilla
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages Moderate
CVE-2023-37465 was published for org.xwiki.contrib:discussions-server (Maven) Jul 27, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
GHSA-7ppr-r889-mcf2 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) High
GHSA-46q4-43ph-c6fr was published for org.http4s:blaze-http_2.12 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser High
GHSA-mhvj-jhpq-885v was published for org.http4s:blaze-http_2.13 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
GHSA-p279-2cqp-84jg was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback Critical
CVE-2026-62379 was published for org.openidentityplatform.openam:openam-core (Maven) Jul 24, 2026
manus-use Credited to manus-use
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass Critical
CVE-2026-62263 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jul 24, 2026
Pig-Tail Credited to Pig-Tail, MarkLee131, baradika, manus-use, and tonghuaroot MarkLee131 MarkLee131
baradika baradika manus-use manus-use tonghuaroot tonghuaroot
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion High
GHSA-v74w-7mr3-4qg3 was published for io.netty:netty-codec-xml (Maven) Jul 24, 2026
violetagg Credited to violetagg
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names Moderate
GHSA-mfg7-5gfp-c4w3 was published for io.netty:netty-codec-dns (Maven) Jul 24, 2026
violetagg Credited to violetagg
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges Moderate
CVE-2026-59949 was published for at.yawk.lz4:lz4-java (Maven) Jul 24, 2026
sectroyer Credited to sectroyer
ProTip! Advisories are also available from the GraphQL API