Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses Moderate
GHSA-7jmw-8259-q9jx was published for github.com/traefik/traefik (Go) Jun 11, 2024
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths Moderate
CVE-2026-32033 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses Moderate
CVE-2026-39409 was published for hono (npm) Apr 8, 2026
r74tech Credited to r74tech
Rack:: Static header_rules bypass via URL-encoded paths Moderate
CVE-2026-34786 was published for rack (RubyGems) Apr 2, 2026
harukioya Credited to harukioya, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
GHSA-89vp-jrxv-24w8 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths Moderate
CVE-2026-7120 was published for @fastify/static (npm) Jul 24, 2026
yuki-matsuhashi Credited to yuki-matsuhashi, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API