Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,473 advisories

Loading
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation High
CVE-2026-55477 was published for github.com/mhsanaei/3x-ui/v2 (Go) Aug 24, 2026
itsamirhn Credited to itsamirhn
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take` High
CVE-2026-63421 was published for @keystone-6/core (npm) Aug 21, 2026
Haxset Credited to Haxset
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address Moderate
GHSA-5p3m-vhh6-9236 was published for stigmem-node (pip) Aug 20, 2026
chaitanyagarware Credited to chaitanyagarware
BuildKit: Custom frontend could bypass Seccomp/AppArmor Moderate
CVE-2026-61711 was published for github.com/moby/buildkit (Go) Aug 19, 2026
Alex0Young Credited to Alex0Young
Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields Moderate
CVE-2026-54543 was published for froxlor/froxlor (Composer) Aug 18, 2026
YHalo-wyh Credited to YHalo-wyh
jmespath.php has CompilerRuntime code injection via unescaped function names Critical
CVE-2026-54133 was published for mtdowling/jmespath.php (Composer) Aug 18, 2026
edorian Credited to edorian
MeshCentral has unsanitized data fields High
GHSA-c7hr-448w-65px was published for meshcentral (npm) Aug 18, 2026
kevthehermit Credited to kevthehermit
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max Low
CVE-2026-61634 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
Alexender676 Credited to Alexender676
RabbitMQ Java client malformed body frame triggers raw command assembler exception Moderate
CVE-2026-63335 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
hibrian827 Credited to hibrian827
package pkcs12: Authentication bypass in Decode functions Moderate
GHSA-mpwr-8vm7-h73f was published for software.sslmate.com/src/go-pkcs12 (Go) Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest Moderate
CVE-2026-45099 was published for github.com/gruntwork-io/terragrunt (Go) Aug 17, 2026
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name High
CVE-2026-55072 was published for pimcore/pimcore (Composer) Aug 13, 2026
dhairya7760 Credited to dhairya7760
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration Moderate
CVE-2026-47132 was published for thorsten/phpmyfaq (Composer) Aug 12, 2026
proochicken Credited to proochicken
Nuxt: Unauthorized Component Instantiation via Server Island Props Moderate
CVE-2026-71318 was published for nuxt (npm) Aug 5, 2026
Electron: window.open features string controls some window options considered privileged Moderate
CVE-2026-70607 was published for electron (npm) Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte Moderate
CVE-2026-70603 was published for electron (npm) Aug 5, 2026
yassine-doyensec Credited to yassine-doyensec, ikkisoft, and maxence-Doyensec ikkisoft ikkisoft
maxence-Doyensec maxence-Doyensec
Ghost: Archived Offers can be Redeemed Moderate
CVE-2026-70589 was published for ghost (npm) Aug 4, 2026
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate Moderate
CVE-2026-59881 was published for aiohttp (pip) Aug 3, 2026
gik2927 Credited to gik2927 and Dreamsorcerer Dreamsorcerer Dreamsorcerer
hi-im-glitchless Credited to hi-im-glitchless
OV-0-VO Credited to OV-0-VO
Socket.IO: Zero-attachment Memory Exhaustion High
CVE-2026-69185 was published for socket.io-parser (npm) Aug 3, 2026
aretekzs Credited to aretekzs, mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk mauriceng98 mauriceng98
Zyy0530 Zyy0530 Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
ProTip! Advisories are also available from the GraphQL API