Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35 advisories

Loading
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop High
CVE-2026-43871 was published for apache/thrift (Composer) Jul 27, 2026
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters High
CVE-2026-49042 was published for org.apache.camel:camel-langchain4j-agent (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel JMS deserialization filter bypass High
CVE-2026-43866 was published for org.apache.camel:camel-activemq (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution High
CVE-2026-43865 was published for org.apache.camel:camel-hazelcast (Maven) Jul 6, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure High
CVE-2026-42527 was published for org.apache.camel:camel-amqp (Maven) Jul 6, 2026
oscerd Credited to oscerd
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization High
CVE-2026-41731 was published for org.springframework.kafka:spring-kafka (Maven) Jun 10, 2026
oscerd Credited to oscerd
Incorrect TLS certificate auth method in Vault High
CVE-2024-2048 was published for github.com/hashicorp/vault (Go) Mar 4, 2024
oscerd Credited to oscerd
Deserialization of Untrusted Data in Apache Camel CassandraQL High
CVE-2024-23114 was published for org.apache.camel:camel-cassandraql (Maven) Feb 20, 2024
oscerd Credited to oscerd
Deserialization of Untrusted Data in Apache Camel SQL High
CVE-2024-22369 was published for org.apache.camel:camel-sql (Maven) Feb 20, 2024
oscerd Credited to oscerd
SMTP smuggling in Apache James High
CVE-2023-51747 was published for org.apache.james:james-server (Maven) Feb 27, 2024
oscerd Credited to oscerd
Apache Ambari: authenticated users could perform command injection to perform RCE High
CVE-2023-50379 was published for org.apache.ambari.contrib.views:ambari-contrib-views (Maven) Feb 27, 2024
oscerd Credited to oscerd
ProTip! Advisories are also available from the GraphQL API