Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,693 advisories

Loading
Ruby json: JSON generator heap buffer overflow when streaming to an IO Low
CVE-2026-54696 was published for json (RubyGems) Jul 23, 2026
susdrip Credited to susdrip
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets Moderate
CVE-2026-55223 was published for com.mchange:c3p0 (Maven) Jul 23, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) Moderate
CVE-2026-53669 was published for react-router (npm) Jul 23, 2026
outring Credited to outring
React Router: Open redirect leading to XSS Moderate
CVE-2026-53668 was published for react-router (npm) Jul 23, 2026
SouadSEBAA Credited to SouadSEBAA
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration Moderate
CVE-2026-53666 was published for react-router (npm) Jul 23, 2026
yoyomiski Credited to yoyomiski
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged Moderate
CVE-2026-53467 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 23, 2026
Serotav Credited to Serotav
find-my-way: DDoS with HTTP2 High
CVE-2026-47219 was published for find-my-way (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077 and mcollina mcollina mcollina
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter) High
CVE-2026-59935 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible infinite loop for not terminated inline images High
CVE-2026-59936 was published for pypdf (pip) Jul 23, 2026
koltiradw Credited to koltiradw and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible long runtimes for repeated malformed cross-reference entries Moderate
CVE-2026-59937 was published for pypdf (pip) Jul 23, 2026
akahane0x46 Credited to akahane0x46 and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible large memory usage for wrong image dimensions Moderate
CVE-2026-59938 was published for pypdf (pip) Jul 23, 2026
MR-SS Credited to MR-SS and stefan6419846 stefan6419846 stefan6419846
offset Credited to offset
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist High
CVE-2026-59931 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
longcalif Credited to longcalif and sondt99 sondt99 sondt99
marc-zollingkoffer-syzygy Credited to marc-zollingkoffer-syzygy
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers High
GHSA-xmf8-cvqr-rfgj was published for @auth/core (npm) Jul 23, 2026
deprrous Credited to deprrous
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass Critical
GHSA-7rqj-j65f-68wh was published for @auth/core (npm) Jul 23, 2026
kakashi-kx Credited to kakashi-kx
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
GHSA-x445-f3h2-j279 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
sm1ee Credited to sm1ee
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner Moderate
GHSA-9cmh-xcqm-5hqr was published for n8n (npm) Jul 22, 2026
thesecguy45 Credited to thesecguy45
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) High
GHSA-pppj-hq3g-57pj was published for jupyterlab (pip) Jul 22, 2026
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab High
GHSA-gx64-gj6p-pc4c was published for jupyterlab (pip) Jul 22, 2026
krassowski Credited to krassowski, MUFFANUJ, and dlqqq MUFFANUJ MUFFANUJ
dlqqq dlqqq
ProTip! Advisories are also available from the GraphQL API