Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

163 advisories

Loading
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check High
GHSA-mf7q-r4rv-jv94 was published for github.com/crossplane/crossplane-runtime/v2 (Go) Aug 27, 2026
tonghuaroot Credited to tonghuaroot and bugbunny-research bugbunny-research bugbunny-research
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation Moderate
CVE-2026-55535 was published for PraisonAI (pip) Aug 25, 2026
vndasunkid Credited to vndasunkid
evertrustai Credited to evertrustai
sour-exploit Credited to sour-exploit
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) Moderate
CVE-2026-53708 was published for mcp-contextforge-gateway (pip) Aug 14, 2026
hewei-gikaku Credited to hewei-gikaku
Electron: Parent process code-sign check is spoofable Moderate
CVE-2026-70597 was published for electron (npm) Aug 5, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Open WebUI: DNS Rebinding SSRF Bypass Moderate
CVE-2026-54020 was published for open-webui (pip) Aug 4, 2026
rezaduty Credited to rezaduty, Classic298, dhyabi2, geo-chen, and bogdancherniy11-sudo Classic298 Classic298
dhyabi2 dhyabi2 geo-chen geo-chen bogdancherniy11-sudo bogdancherniy11-sudo
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding High
CVE-2026-55391 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
Budibase: SSRF via DNS rebinding in the REST datasource integration High
CVE-2026-73410 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219 Moderate
GHSA-56m6-8q75-f2rw was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Netty: TOCTOU in OcspServerCertificateValidator High
CVE-2026-56822 was published for io.netty:netty-handler-ssl-ocsp (Maven) Jul 22, 2026
violetagg Credited to violetagg
Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution High
GHSA-725q-c4vp-q4cg was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
chdanielmueller Credited to chdanielmueller
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption High
CVE-2026-53517 was published for @better-auth/oauth-provider (npm) Jul 7, 2026
chdanielmueller Credited to chdanielmueller
uucore: safe_traversal TOCTOU protection only enabled on Linux Low
CVE-2026-35362 was published for uucore (Rust) Jul 6, 2026
mkdir: -m exposes directory with umask perms before chmod (race window) Low
CVE-2026-35353 was published for uu_mkdir (Rust) Jul 6, 2026
install -D: symlink race in directory creation allows arbitrary file overwrite Moderate
CVE-2026-35356 was published for uu_install (Rust) Jul 6, 2026
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite Moderate
CVE-2026-35355 was published for uu_install (Rust) Jul 6, 2026
OpenClaw: Combined POSIX shell options could confuse exec revalidation High
CVE-2026-53806 was published for openclaw (npm) Jul 2, 2026
YLChen-007 Credited to YLChen-007
OpenClaw: Node pairing reconnection could confuse approval scope state Moderate
CVE-2026-53838 was published for openclaw (npm) Jul 2, 2026
YLChen-007 Credited to YLChen-007
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion High
CVE-2026-53831 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
ProTip! Advisories are also available from the GraphQL API