Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

14 advisories

Loading
OctoPrint has XSS in its Suppressed Command Notifications Moderate
CVE-2026-35163 was published for OctoPrint (pip) Jun 23, 2026
jacopotediosi Credited to jacopotediosi and cookesan cookesan cookesan
n8n: Prototype Pollution enables confused-deputy execution via public webhooks Moderate
CVE-2026-54306 was published for n8n (npm) Jun 16, 2026
sm1ee Credited to sm1ee and cookesan cookesan cookesan
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` Moderate
CVE-2026-54288 was published for hono (npm) Jun 16, 2026
Rootingg Credited to Rootingg and cookesan cookesan cookesan
Rootingg Credited to Rootingg and cookesan cookesan cookesan
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Moderate
CVE-2026-54286 was published for hono (npm) Jun 16, 2026
hanacus87 Credited to hanacus87 and cookesan cookesan cookesan
Rootingg Credited to Rootingg and cookesan cookesan cookesan
alcls01111 Credited to alcls01111, cookesan, and sealonohana cookesan cookesan
sealonohana sealonohana
Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple times Moderate
CVE-2025-31135 was published for github.com/phires/go-guerrilla (Go) Apr 1, 2025
Zenexer Credited to Zenexer and cookesan cookesan cookesan
cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs Moderate
GHSA-r4pg-vg54-wxx4 was published for github.com/cert-manager/cert-manager (Go) Nov 20, 2024
cookesan Credited to cookesan
CoreDNS Cache Poisoning via a birthday attack Moderate
CVE-2023-30464 was published for github.com/coredns/coredns (Go) Sep 18, 2024
cookesan Credited to cookesan
CosmWasm wasmd has large address count in ValidateBasic Moderate
GHSA-m3rh-cvr5-x6q4 was published for github.com/CosmWasm/wasmd (Go) Aug 8, 2024
sushiwushi Credited to sushiwushi and cookesan cookesan cookesan
1Panel arbitrary file write vulnerability Moderate
CVE-2024-34352 was published for github.com/1Panel-dev/1Panel (Go) May 9, 2024
an5er Credited to an5er and cookesan cookesan cookesan
Kube-proxy may unintentionally forward traffic Moderate
CVE-2021-25736 was published for k8s.io/kubernetes (Go) Oct 30, 2023
cookesan Credited to cookesan
Denial of service via insufficient metadata validation Moderate
GHSA-p93v-m2r2-4387 was published for github.com/google/fscrypt (Go) Mar 1, 2022
mgerstner Credited to mgerstner and cookesan cookesan cookesan
ProTip! Advisories are also available from the GraphQL API