Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,755 advisories

Loading
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets Moderate
CVE-2026-75523 was published for Steeltoe.Management.Endpoint (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Grav: Stored XSS via Markdown audio/video media <source> URL Moderate
CVE-2026-75831 was published for getgrav/grav (Composer) Sep 17, 2026
alimony Credited to alimony
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
Grav: Stored XSS via quoted-attribute bypass in detectXss Moderate
CVE-2026-72832 was published for getgrav/grav (Composer) Sep 17, 2026
koyokr Credited to koyokr
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target Moderate
CVE-2026-85717 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request Moderate
CVE-2026-85720 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service High
CVE-2026-85721 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses Low
CVE-2026-85716 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
SSH.NET: ScpClient allows server-side RCE via default SCP path handling High
CVE-2026-85756 was published for SSH.NET (NuGet) Sep 17, 2026
Nadav0077 Credited to Nadav0077
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth Moderate
CVE-2026-73245 was published for io.kestra:kestra (Maven) Sep 17, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation Moderate
CVE-2026-69147 was published for vllm (pip) Sep 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images High
CVE-2026-69089 was published for getgrav/grav (Composer) Sep 17, 2026
nihaddhuseynli Credited to nihaddhuseynli
adamyordan Credited to adamyordan
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing Moderate
CVE-2026-85732 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
manus-use Credited to manus-use
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) High
CVE-2026-85731 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata High
CVE-2026-73247 was published for io.kestra:core (Maven) Sep 17, 2026
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation High
CVE-2026-65608 was published for getgrav/grav (Composer) Sep 17, 2026
haftoe Credited to haftoe
Pig-Tail Credited to Pig-Tail
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client High
CVE-2026-77412 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr Critical
CVE-2026-77411 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation High
CVE-2026-77410 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow Critical
CVE-2026-77408 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields High
CVE-2026-77407 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration High
CVE-2026-77406 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser Critical
CVE-2026-77405 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
ProTip! Advisories are also available from the GraphQL API