Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13 advisories

Loading
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths Moderate
CVE-2026-7120 was published for @fastify/static (npm) Jul 24, 2026
yuki-matsuhashi Credited to yuki-matsuhashi, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass Critical
GHSA-7rqj-j65f-68wh was published for @auth/core (npm) Jul 23, 2026
kakashi-kx Credited to kakashi-kx
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
GHSA-89vp-jrxv-24w8 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass Critical
CVE-2026-44180 was published for jupyter_enterprise_gateway (pip) Jun 3, 2026
ben-elttam Credited to ben-elttam, matt-elttam, daniel-elttam, and lresende matt-elttam matt-elttam
daniel-elttam daniel-elttam lresende lresende
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring High
CVE-2026-42462 was published for @fedify/fedify (npm) May 26, 2026
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git High
CVE-2026-45022 was published for github.com/go-git/go-git/v5 (Go) May 11, 2026
adityasaky Credited to adityasaky, wlynch, patzielinski, bugbunny-research, and wayphinder wlynch wlynch
patzielinski patzielinski bugbunny-research bugbunny-research wayphinder wayphinder
Rack:: Static header_rules bypass via URL-encoded paths Moderate
CVE-2026-34786 was published for rack (RubyGems) Apr 2, 2026
harukioya Credited to harukioya, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses Moderate
CVE-2026-39409 was published for hono (npm) Apr 8, 2026
r74tech Credited to r74tech
Vite: `server.fs.deny` bypassed with queries High
CVE-2026-39364 was published for vite (npm) Apr 6, 2026
odgrso Credited to odgrso, ritikchaddha, neo-ai-engineer, instantraaamen, fg0x0, jonathanwd, kq5y, and bluwy ritikchaddha ritikchaddha
neo-ai-engineer neo-ai-engineer instantraaamen instantraaamen fg0x0 fg0x0 jonathanwd jonathanwd kq5y kq5y bluwy bluwy
FrankenPHP's unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FrankenPHP High
CVE-2026-24895 was published for github.com/dunglas/frankenphp (Go) Feb 12, 2026
AbdrrahimDahmani Credited to AbdrrahimDahmani, dunglas, and hans362 dunglas dunglas
hans362 hans362
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths Moderate
CVE-2026-32033 was published for openclaw (npm) Mar 3, 2026
tdjackey Credited to tdjackey
eternal-flame-AD Credited to eternal-flame-AD and Pr0methean Pr0methean Pr0methean
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses Moderate
GHSA-7jmw-8259-q9jx was published for github.com/traefik/traefik (Go) Jun 11, 2024
ProTip! Advisories are also available from the GraphQL API