Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

107 advisories

Loading
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability Critical
CVE-2026-65182 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability Critical
CVE-2026-68525 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability Critical
CVE-2026-65905 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Ranger has a Command Injection vulnerability Critical
CVE-2026-28672 was published for org.apache.ranger:ranger (Maven) Aug 10, 2026
oscerd Credited to oscerd
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop High
CVE-2026-43871 was published for apache/thrift (Composer) Jul 27, 2026
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters High
CVE-2026-49042 was published for org.apache.camel:camel-langchain4j-agent (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy Critical
CVE-2026-56140 was published for org.apache.camel:camel-aws2-sns (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter Moderate
CVE-2026-48206 was published for org.apache.camel:camel-jira (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter Moderate
CVE-2026-49099 was published for org.apache.camel:camel-salesforce (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
ProTip! Advisories are also available from the GraphQL API