Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,673 advisories

Loading
sm1ee Credited to sm1ee
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner Moderate
GHSA-9cmh-xcqm-5hqr was published for n8n (npm) Jul 22, 2026
thesecguy45 Credited to thesecguy45
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) High
GHSA-pppj-hq3g-57pj was published for jupyterlab (pip) Jul 22, 2026
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab High
GHSA-gx64-gj6p-pc4c was published for jupyterlab (pip) Jul 22, 2026
krassowski Credited to krassowski, MUFFANUJ, and dlqqq MUFFANUJ MUFFANUJ
dlqqq dlqqq
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
GHSA-89vp-jrxv-24w8 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab PluginManager lock-rule enforcement bypass Moderate
GHSA-h5v5-8746-g7mm was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
Next.js: Server-Side Request Forgery in Server Actions on custom servers High
CVE-2026-64649 was published for next (npm) Jul 22, 2026
oxqnd Credited to oxqnd
Next.js: Cache confusion of response bodies for requests with bodies Moderate
CVE-2026-64648 was published for next (npm) Jul 22, 2026
rafabd1 Credited to rafabd1
yorukot Credited to yorukot
Next.js: Unbounded Server Action payload in Edge runtime Moderate
CVE-2026-64646 was published for next (npm) Jul 22, 2026
Next.js: Denial of Service in the Image Optimization API using SVGs Moderate
CVE-2026-64644 was published for next (npm) Jul 22, 2026
idealinsane Credited to idealinsane
Next.js: Unauthenticated disclosure of internal Server Function endpoints Moderate
CVE-2026-64643 was published for next (npm) Jul 22, 2026
randomguy6407 Credited to randomguy6407
Next.js: Denial of Service in App Router using Server Actions High
CVE-2026-64641 was published for next (npm) Jul 22, 2026
jviide Credited to jviide
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests High
CVE-2024-7708 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
kimmerin Credited to kimmerin and pmneo pmneo pmneo
Eclipse Jetty: Path parameter traversal Moderate
CVE-2026-8384 was published for org.eclipse.jetty:jetty-util (Maven) Jul 22, 2026
jweny Credited to jweny
Eclipse Jetty: HTTP Authority/Host mismatch Moderate
CVE-2026-6790 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections Moderate
CVE-2026-10051 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution High
CVE-2026-10050 was published for org.eclipse.jetty.ee8:jetty-ee8-security (Maven) Jul 22, 2026
hrykx-zy Credited to hrykx-zy
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data Moderate
CVE-2026-65589 was published for n8n (npm) Jul 22, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
ProTip! Advisories are also available from the GraphQL API