Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23 advisories

Loading
Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability Critical
CVE-2024-26580 was published for org.apache.inlong:manager-common (Maven) Mar 6, 2024
oscerd Credited to oscerd
Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification Critical
CVE-2024-27317 was published for org.apache.pulsar:pulsar-functions-worker (Maven) Mar 12, 2024
oscerd Credited to oscerd
Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation Critical
CVE-2024-29868 was published for org.apache.streampipes:streampipes-resource-management (Maven) Jun 24, 2024
oscerd Credited to oscerd
Apache Zeppelin remote code execution by adding malicious JDBC connection string Critical
CVE-2024-31864 was published for org.apache.zeppelin:zeppelin-jdbc (Maven) Apr 9, 2024
oscerd Credited to oscerd
Apache James server: Privilege escalation via JMX pre-authentication deserialization Critical
CVE-2023-51518 was published for org.apache.james:james-server (Maven) Feb 27, 2024
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Camel DNS Has Improper Input Validation, Leading to Server-Side Request Forgery (SSRF) Critical
CVE-2026-48205 was published for org.apache.camel:camel-dns (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel: camel-mongodb-gridfs producer allows GridFS operation override and NoSQL operator injection via unfiltered  gridfs.*  HTTP headers Critical
CVE-2026-48204 was published for org.apache.camel:camel-mongodb-gridfs (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer Critical
CVE-2026-40047 was published for org.apache.camel:camel-docling (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache Camel-AWS2-SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy Critical
CVE-2026-56140 was published for org.apache.camel:camel-aws2-sns (Maven) Jul 6, 2026
oscerd Credited to oscerd
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage Critical
CVE-2026-40860 was published for org.apache.camel:camel-activemq (Maven) Apr 27, 2026
oscerd Credited to oscerd
oscerd Credited to oscerd
oscerd Credited to oscerd
Apache Ranger has a Command Injection vulnerability Critical
CVE-2026-28672 was published for org.apache.ranger:ranger (Maven) Aug 10, 2026
oscerd Credited to oscerd
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability Critical
CVE-2026-65182 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability Critical
CVE-2026-65905 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability Critical
CVE-2026-68525 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
ProTip! Advisories are also available from the GraphQL API