Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

942 advisories

Loading
Apache Tomcat's FORM authentication process has an Incorrect Authorization vulnerability Critical
CVE-2026-68525 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Tomcat's DIGEST authenticator has an Authentication Bypass by Capture-replay vulnerability Critical
CVE-2026-65905 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Tomcat has an Improper Access Control, Incorrect Authorization vulnerability Critical
CVE-2026-65182 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Aug 26, 2026
oscerd Credited to oscerd
Apache Ranger has a Command Injection vulnerability Critical
CVE-2026-28672 was published for org.apache.ranger:ranger (Maven) Aug 10, 2026
oscerd Credited to oscerd
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames Critical
CVE-2026-25534 was published for io.spinnaker.clouddriver:clouddriver-artifacts (Maven) Mar 16, 2026
jaydhulia Credited to jaydhulia, jasonmcintosh, and sealbenb jasonmcintosh jasonmcintosh
sealbenb sealbenb
hermes-management is vulnerable to RCE due to Apache commons-jxpath Critical
GHSA-2gh6-wc3m-g37f was published for pl.allegro.tech.hermes:hermes-management (Maven) Sep 17, 2024
sealbenb Credited to sealbenb
Apache Pinot Vulnerable to Authentication Bypass Critical
CVE-2024-56325 was published for org.apache.pinot:pinot-broker (Maven) Apr 1, 2025
AnonySE26 Credited to AnonySE26 and sealbenb sealbenb sealbenb
Apache Dolphinscheduler Code Injection vulnerability Critical
CVE-2024-43202 was published for org.apache.dolphinscheduler:dolphinscheduler-task-api (Maven) Aug 20, 2024
sealbenb Credited to sealbenb
Apache Polaris has an Improper Input Validation issue Critical
CVE-2026-42812 was published for org.apache.polaris:polaris-runtime-service (Maven) May 4, 2026
sealbenb Credited to sealbenb
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications Critical
CVE-2024-38821 was published for org.springframework.security:spring-security-web (Maven) Oct 28, 2024
sealbenb Credited to sealbenb
Apache Ranger UI vulnerable to Server Side Request Forgery Critical
CVE-2024-45479 was published for org.apache.ranger:ranger (Maven) Jan 22, 2025
sealbenb Credited to sealbenb
Apache Tomcat - HTTP/2 request headers not validated Critical
CVE-2026-41293 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 12, 2026
sealbenb Credited to sealbenb
Keycloak: Unauthenticated account takeover via reset-credentials flow bypass Critical
CVE-2026-18963 was published for org.keycloak:keycloak-services (Maven) Aug 18, 2026
madmuffin1 Credited to madmuffin1, greiffmode, and pv-rudger greiffmode greiffmode
pv-rudger pv-rudger
oscerd Credited to oscerd
Marnick39 Credited to Marnick39
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Critical
CVE-2026-55559 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
MarkLee131 Credited to MarkLee131 and manus-use manus-use manus-use
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` Critical
CVE-2026-55511 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
Yanchon918s Credited to Yanchon918s and manus-use manus-use manus-use
oscerd Credited to oscerd
Apache camel-jms, camel-sjms, camel-sjms2 and camel-amqp: Unsafe Deserialization of JMS ObjectMessage Critical
CVE-2026-40860 was published for org.apache.camel:camel-activemq (Maven) Apr 27, 2026
oscerd Credited to oscerd
ProTip! Advisories are also available from the GraphQL API