Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,104 advisories

Loading
io.moquette:moquette-broker has a Missing Authorization issue High
CVE-2026-85058 was published for io.moquette:moquette-broker (Maven) Sep 18, 2026
Fireees Credited to Fireees and Robin-szu Robin-szu Robin-szu
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue Critical
CVE-2025-53837 was published for org.xwiki.rendering:xwiki-rendering-xml (Maven) Sep 18, 2026
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text High
CVE-2026-77615 was published for org.opencastproject:opencast-engage-paella-player-7 (Maven) Sep 18, 2026
kah-ja Credited to kah-ja
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service High
CVE-2026-81876 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service High
CVE-2026-81875 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target Moderate
CVE-2026-85717 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request Moderate
CVE-2026-85720 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service High
CVE-2026-85721 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient doesn't verify SCRAM and Digest mutual-authentication responses Low
CVE-2026-85716 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth Moderate
CVE-2026-73245 was published for io.kestra:kestra (Maven) Sep 17, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata High
CVE-2026-73247 was published for io.kestra:core (Maven) Sep 17, 2026
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root Low
CVE-2026-86071 was published for com.github.junrar:junrar (Maven) Sep 17, 2026
smaeljaish771 Credited to smaeljaish771
MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiated LOCAL INFILE requests Low
CVE-2026-61700 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Sep 17, 2026
tharavel Credited to tharavel
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799) High
CVE-2026-63126 was published for com.squareup.wire:wire-runtime (Maven) Sep 17, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement High
CVE-2026-75516 was published for com.rabbitmq:amqp-client (Maven) Sep 17, 2026
lucianjohnhouse Credited to lucianjohnhouse
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE High
CVE-2026-88975 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
stasimus Credited to stasimus and rossabaker rossabaker rossabaker
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators Moderate
CVE-2026-69201 was published for org.http4s:http4s-server_2.12 (Maven) Sep 15, 2026
Lasering Credited to Lasering, rossabaker, and samspills rossabaker rossabaker
samspills samspills
Http4s Ember HTTP/2: unbounded continuation frame accumulation High
CVE-2026-69218 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, morgen-peschke, and reardonj samspills samspills
morgen-peschke morgen-peschke reardonj reardonj
Http4s: Ember chunk parser lenience (TE.TE request smuggling) Moderate
CVE-2026-69216 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII, rossabaker, and morgen-peschke rossabaker rossabaker
morgen-peschke morgen-peschke
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin Moderate
CVE-2026-69215 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, ERobertGII, and samspills ERobertGII ERobertGII
samspills samspills
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain Moderate
CVE-2026-69214 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Http4s Ember HTTP/2 has an unbounded outbound frame queue High
CVE-2026-69213 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
Http4s: DigestAuth nonce map grows unbounded High
CVE-2026-69208 was published for org.http4s:http4s-ember-server_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Http4s: DigestAuth allows replay of captured requests Moderate
CVE-2026-69206 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker and morgen-peschke morgen-peschke morgen-peschke
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling) High
CVE-2026-69205 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
ProTip! Advisories are also available from the GraphQL API