Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

53 advisories

Loading
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks Moderate
CVE-2026-56812 was published for phoenix (Erlang) Sep 3, 2026
PJUllrich Credited to PJUllrich, maennchen, and SteffenDE maennchen maennchen
SteffenDE SteffenDE
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
CVE-2026-73430 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
CVE-2026-73429 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
protobufjs : Schema-derived names can shadow runtime-significant properties Moderate
CVE-2026-54269 was published for protobufjs (npm) Jun 15, 2026
acorn421 Credited to acorn421 and dcodeIO dcodeIO dcodeIO
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) Moderate
CVE-2026-35366 was published for uu_printenv (Rust) Jul 6, 2026
Duplicate Advisory: uutils coreutils has an Improper Check for Unusual or Exceptional Conditions Moderate
GHSA-7259-cwhx-3xx3 was published for coreutils (Rust) Apr 22, 2026 withdrawn
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS) Moderate
CVE-2026-35369 was published for uu_kill (Rust) Jul 6, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers Moderate
GHSA-c8w6-x74f-vmg3 was published for zebra-rpc (Rust) Jul 2, 2026
robustfengbin Credited to robustfengbin, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
LucyEgan Credited to LucyEgan
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing Moderate
CVE-2026-4915 was published for github.com/mattermost/mattermost-server (Go) May 26, 2026
LinZiyuu Credited to LinZiyuu
LinZiyuu Credited to LinZiyuu
Mattermost doesn't validate the response body of proxied images Moderate
CVE-2026-4054 was published for github.com/mattermost/mattermost-server (Go) May 15, 2026
Admidio Missing Minimum Administrator Check in Role Membership Removal Moderate
CVE-2026-41662 was published for admidio/admidio (Composer) Apr 29, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
nimiq-blockchain: Peer-triggerable panic during history sync Moderate
CVE-2026-34066 was published for nimiq-blockchain (Rust) Apr 22, 2026
1seal Credited to 1seal and ii-cruz ii-cruz ii-cruz
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation Moderate
CVE-2026-40343 was published for github.com/free5gc/udr (Go) Apr 21, 2026
Giancannella Credited to Giancannella
Giancannella Credited to Giancannella and FrancescoDAlterio FrancescoDAlterio FrancescoDAlterio
Cosign's verify-blob-attestation reports false positive when payload parsing fails Moderate
CVE-2026-39395 was published for github.com/sigstore/cosign (Go) Apr 8, 2026
kodareef5 Credited to kodareef5
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds Moderate
CVE-2026-20719 was published for github.com/mattermost/mattermost/server/v8 (Go) Mar 25, 2026
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx Moderate
GHSA-fqpg-rq76-99pq was published for github.com/jackc/pgx/v5 (Go) Jul 5, 2024
silversub Credited to silversub
go-tuf affected by client DoS via malformed server response Moderate
CVE-2026-23991 was published for github.com/theupdateframework/go-tuf/v2 (Go) Jan 21, 2026
1seal Credited to 1seal, kommendorkapten, and rdimitrov kommendorkapten kommendorkapten
rdimitrov rdimitrov
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf Moderate
CVE-2023-23931 was published for cryptography (pip) Feb 7, 2023
InventoryGui affected by item duplication in GUIs which use GuiStorageElement Moderate
CVE-2025-62783 was published for de.themoep:inventorygui (Maven) Oct 27, 2025
FaMa91 Credited to FaMa91
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions Moderate
CVE-2025-54463 was published for github.com/mattermost/mattermost-plugin-confluence (Go) Aug 11, 2025
ProTip! Advisories are also available from the GraphQL API