Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

416 advisories

Loading
Apache Tomcat Improper Input Validation vulnerability High
CVE-2023-46589 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Nov 28, 2023
biehl1 Credited to biehl1 and aruneko aruneko aruneko
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass Moderate
CVE-2025-71381 was published for hono (npm) Oct 24, 2025
gigatechcode Credited to gigatechcode
undici vulnerable to downstream response splitting via retry interceptor Low
CVE-2026-18540 was published for undici (npm) Sep 29, 2026
samuel871211 Credited to samuel871211, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses... Moderate Unreviewed
CVE-2026-100724 was published Sep 27, 2026
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies High
CVE-2026-65838 was published for github.com/zalando/skipper (Go) Jul 17, 2026
sec-reex Credited to sec-reex and deepakravisankar deepakravisankar deepakravisankar
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact` Moderate
GHSA-jrpc-7vxp-69p6 was published for org.http4k:http4k-core (Maven) Jun 19, 2026
massif-01 Credited to massif-01
ProTip! Advisories are also available from the GraphQL API