Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

164 advisories

Loading
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader High
CVE-2026-87996 was published for open-webui (pip) Sep 10, 2026
baeseungwon1010 Credited to baeseungwon1010 and Classic298 Classic298 Classic298
ONNX: TOCTOU arbitrary file read/write in save_external_dat High
CVE-2026-49114 was published for onnx (pip) Apr 1, 2026
tsigouris007 Credited to tsigouris007 and kpatsakis kpatsakis kpatsakis
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check High
GHSA-mf7q-r4rv-jv94 was published for github.com/crossplane/crossplane-runtime/v2 (Go) Aug 27, 2026
tonghuaroot Credited to tonghuaroot and bugbunny-research bugbunny-research bugbunny-research
OpenClaw: Node pairing reconnection could confuse approval scope state Moderate
CVE-2026-53838 was published for openclaw (npm) Jul 2, 2026
YLChen-007 Credited to YLChen-007
Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state Moderate
GHSA-c85p-9pvr-f7f5 was published for openclaw (npm) Jun 13, 2026 withdrawn
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion High
CVE-2026-53831 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
Duplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion High
GHSA-gwcq-453v-2frr was published for openclaw (npm) Jun 13, 2026 withdrawn
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation Moderate
CVE-2026-55535 was published for PraisonAI (pip) Aug 25, 2026
vndasunkid Credited to vndasunkid
evertrustai Credited to evertrustai
sour-exploit Credited to sour-exploit
Apache CXF OAuth2 TOCTOU Race Condition in Refresh Token Processing High
CVE-2026-50631 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition Moderate
CVE-2026-9796 was published for org.keycloak:keycloak-server (Maven) May 28, 2026
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
Budibase: SSRF via DNS rebinding in the REST datasource integration High
CVE-2026-73410 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation High
CVE-2026-54353 was published for @budibase/backend-core (npm) Jun 22, 2026
Artex09 Credited to Artex09
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse Low
CVE-2026-6733 was published for undici (npm) Jun 19, 2026
mcollina Credited to mcollina, UlisesGascon, and EchoTydes UlisesGascon UlisesGascon
EchoTydes EchoTydes
Electron: Parent process code-sign check is spoofable Moderate
CVE-2026-70597 was published for electron (npm) Aug 5, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Open WebUI: DNS Rebinding SSRF Bypass Moderate
CVE-2026-54020 was published for open-webui (pip) Aug 4, 2026
rezaduty Credited to rezaduty, Classic298, dhyabi2, geo-chen, and bogdancherniy11-sudo Classic298 Classic298
dhyabi2 dhyabi2 geo-chen geo-chen bogdancherniy11-sudo bogdancherniy11-sudo
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding High
CVE-2026-55391 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219 Moderate
GHSA-56m6-8q75-f2rw was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Netty: TOCTOU in OcspServerCertificateValidator High
CVE-2026-56822 was published for io.netty:netty-handler-ssl-ocsp (Maven) Jul 22, 2026
violetagg Credited to violetagg
ProTip! Advisories are also available from the GraphQL API