Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,755 advisories

Loading
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection High
CVE-2026-77404 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation High
CVE-2026-77403 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root Low
CVE-2026-86071 was published for com.github.junrar:junrar (Maven) Sep 17, 2026
smaeljaish771 Credited to smaeljaish771
taisehub Credited to taisehub, dataflake, jensens, and pog007 dataflake dataflake
jensens jensens pog007 pog007
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution High
CVE-2026-76825 was published for RestrictedPython (pip) Sep 17, 2026
icemac Credited to icemac, kakashi-1337, and dataflake kakashi-1337 kakashi-1337
dataflake dataflake
ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion High
CVE-2026-85715 was published for exifreader (npm) Sep 17, 2026
alienkeric Credited to alienkeric
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests Low
CVE-2026-61700 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Sep 17, 2026
tharavel Credited to tharavel
suryadina Credited to suryadina
sanic chunked trailer request smuggling allows hidden second request execution Moderate
CVE-2026-85078 was published for sanic (pip) Sep 17, 2026
lalalala5678 Credited to lalalala5678
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site High
CVE-2026-63506 was published for @tinacms/auth (npm) Sep 17, 2026
riodrwn Credited to riodrwn
Redocly CLI: Path traversal when using `split` command Moderate
CVE-2026-63225 was published for @redocly/cli (npm) Sep 17, 2026
thegr1ffyn Credited to thegr1ffyn
Pocketbase: Unhandled panic in worker goroutines High
CVE-2026-82410 was published for github.com/pocketbase/pocketbase (Go) Sep 17, 2026
gigioneggiando Credited to gigioneggiando
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer Moderate
CVE-2026-61449 was published for getgrav/grav (Composer) Sep 17, 2026
iliaal Credited to iliaal
afldl Credited to afldl
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799) High
CVE-2026-63126 was published for com.squareup.wire:wire-runtime (Maven) Sep 17, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass Moderate
CVE-2026-77360 was published for @orpc/server (npm) Sep 17, 2026
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement High
CVE-2026-75516 was published for com.rabbitmq:amqp-client (Maven) Sep 17, 2026
lucianjohnhouse Credited to lucianjohnhouse
Marten's LINQ provider has SQL injection via unescaped string literals Critical
CVE-2026-75513 was published for Marten (NuGet) Sep 17, 2026
svenclaesson Credited to svenclaesson
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter Moderate
CVE-2026-59823 was published for litellm (pip) Sep 17, 2026
brettgus Credited to brettgus
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument on Windows High
CVE-2026-71538 was published for @cyclonedx/cyclonedx-npm (npm) Sep 17, 2026
fortress07 Credited to fortress07 and jkowalleck jkowalleck jkowalleck
squinard1478 Credited to squinard1478
Vendure: Shop API list queries can return non-public entities when filterOperator is OR Moderate
CVE-2026-63461 was published for @vendure/core (npm) Sep 17, 2026
pavelkohout396 Credited to pavelkohout396
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends High
CVE-2026-63460 was published for vendure/core (npm) Sep 17, 2026
de3erve Credited to de3erve
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions High
CVE-2026-63459 was published for @vendure/dashboard (npm) Sep 17, 2026
squinard1478 Credited to squinard1478
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter Moderate
CVE-2026-61793 was published for nuxt-og-image (npm) Sep 17, 2026
hypnguyen1209 Credited to hypnguyen1209
ProTip! Advisories are also available from the GraphQL API