Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

53 advisories

Loading
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data High
GHSA-p7mv-53f2-4cwj was published for github.com/cometbft/cometbft (Go) Nov 6, 2024
corverroos Credited to corverroos, cookesan, and simonmorley cookesan cookesan
simonmorley simonmorley
Pig-Tail Credited to Pig-Tail and cookesan cookesan cookesan
OctoPrint has possible file exfiltration via query parameters on upload endpoints High
CVE-2026-54134 was published for OctoPrint (pip) Jun 23, 2026
seankohjs Credited to seankohjs, jacopotediosi, and cookesan jacopotediosi jacopotediosi
cookesan cookesan
OctoPrint has XSS in its Suppressed Command Notifications Moderate
CVE-2026-35163 was published for OctoPrint (pip) Jun 23, 2026
jacopotediosi Credited to jacopotediosi and cookesan cookesan cookesan
alcls01111 Credited to alcls01111, cookesan, and sealonohana cookesan cookesan
sealonohana sealonohana
Astro: Host header SSRF in prerendered error page fetch High
CVE-2026-54299 was published for astro (npm) Jun 16, 2026
5ud0er Credited to 5ud0er and cookesan cookesan cookesan
Astro: Reflected XSS via unescaped slot name High
CVE-2026-50146 was published for astro (npm) Jun 16, 2026
floudeciel Credited to floudeciel and cookesan cookesan cookesan
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Moderate
CVE-2026-54286 was published for hono (npm) Jun 16, 2026
hanacus87 Credited to hanacus87 and cookesan cookesan cookesan
fg0x0 Credited to fg0x0 and cookesan cookesan cookesan
Rootingg Credited to Rootingg and cookesan cookesan cookesan
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` Moderate
CVE-2026-54288 was published for hono (npm) Jun 16, 2026
Rootingg Credited to Rootingg and cookesan cookesan cookesan
Rootingg Credited to Rootingg and cookesan cookesan cookesan
n8n: Prototype Pollution enables confused-deputy execution via public webhooks Moderate
CVE-2026-54306 was published for n8n (npm) Jun 16, 2026
sm1ee Credited to sm1ee and cookesan cookesan cookesan
nginx-ui Backup Restore Allows Tampering with Encrypted Backups Critical
CVE-2026-33026 was published for github.com/0xJacky/Nginx-UI (Go) Mar 30, 2026
dapickle Credited to dapickle and cookesan cookesan cookesan
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF High
CVE-2024-23828 was published for github.com/0xJacky/Nginx-UI (Go) Jan 29, 2024
Elleuch-x1 Credited to Elleuch-x1, 0xJacky, and cookesan 0xJacky 0xJacky
cookesan cookesan
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature Critical
CVE-2024-23827 was published for github.com/0xJacky/Nginx-UI (Go) Jan 29, 2024
Elleuch-x1 Credited to Elleuch-x1, 0xJacky, and cookesan 0xJacky 0xJacky
cookesan cookesan
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270) High
CVE-2024-22196 was published for github.com/0xJacky/Nginx-UI (Go) Jan 11, 2024
jorgectf Credited to jorgectf, Hintay, and cookesan Hintay Hintay
cookesan cookesan
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269) High
CVE-2024-22197 was published for github.com/0xJacky/Nginx-UI (Go) Jan 11, 2024
jorgectf Credited to jorgectf, Hintay, and cookesan Hintay Hintay
cookesan cookesan
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268) High
CVE-2024-22198 was published for github.com/0xJacky/Nginx-UI (Go) Jan 11, 2024
jorgectf Credited to jorgectf, Hintay, and cookesan Hintay Hintay
cookesan cookesan
Kube-proxy may unintentionally forward traffic Moderate
CVE-2021-25736 was published for k8s.io/kubernetes (Go) Oct 30, 2023
cookesan Credited to cookesan
CosmWasm wasmd has large address count in ValidateBasic Moderate
GHSA-m3rh-cvr5-x6q4 was published for github.com/CosmWasm/wasmd (Go) Aug 8, 2024
sushiwushi Credited to sushiwushi and cookesan cookesan cookesan
OS Command Injection in install-package Critical
CVE-2020-7629 was published for install-package (npm) Feb 10, 2022
cookesan Credited to cookesan
OS Command Injection in git-add-remote Critical
CVE-2020-7630 was published for git-add-remote (npm) Feb 10, 2022
cookesan Credited to cookesan
OS Command Injection in node-key-sender Critical
CVE-2020-7627 was published for node-key-sender (npm) Feb 10, 2022
cookesan Credited to cookesan
Injection in op-browser Critical
CVE-2020-7625 was published for op-browser (npm) Feb 10, 2022
cookesan Credited to cookesan
ProTip! Advisories are also available from the GraphQL API