Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

416 advisories

Loading
undici vulnerable to downstream response splitting via retry interceptor Low
CVE-2026-18540 was published for undici (npm) Sep 29, 2026
samuel871211 Credited to samuel871211, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses... Moderate Unreviewed
CVE-2026-100724 was published Sep 27, 2026
sanic chunked trailer request smuggling allows hidden second request execution Moderate
CVE-2026-85078 was published for sanic (pip) Sep 17, 2026
lalalala5678 Credited to lalalala5678
Http4s: Ember chunk parser lenience (TE.TE request smuggling) Moderate
CVE-2026-69216 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII, rossabaker, and morgen-peschke rossabaker rossabaker
morgen-peschke morgen-peschke
ProTip! Advisories are also available from the GraphQL API