Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,666 advisories

Loading
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77415 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77414 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution High
CVE-2026-68508 was published for hydra-core (pip) Aug 21, 2026
guwu1017 Credited to guwu1017
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
JSONata: Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77413 was published for jsonata (npm) Aug 21, 2026
peaktwilight Credited to peaktwilight and c0rydoras c0rydoras c0rydoras
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding High
CVE-2026-77354 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing Critical
CVE-2026-61539 was published for xinference (pip) Aug 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS High
CVE-2026-76905 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation High
CVE-2026-64679 was published for github.com/runatlantis/atlantis (Go) Aug 21, 2026
shblue21 Credited to shblue21
Keystone vulnerable to `graphql.maxTake` bypass with negative `take` High
CVE-2026-63421 was published for @keystone-6/core (npm) Aug 21, 2026
Haxset Credited to Haxset
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers Critical
CVE-2026-76904 was published for org.geotools.jdbc:gt-jdbc-postgis (Maven) Aug 21, 2026
qquang Credited to qquang, mrlihd, PhilipPhil, Quikko, jodygarnett, h1ei1, and 4ra1n mrlihd mrlihd
PhilipPhil PhilipPhil Quikko Quikko jodygarnett jodygarnett h1ei1 h1ei1 4ra1n 4ra1n
skeletonsec Credited to skeletonsec
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Moderate
CVE-2026-67448 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
arpitjain099 Credited to arpitjain099
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Moderate
CVE-2026-67447 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
rexpository Credited to rexpository
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys Moderate
CVE-2026-55451 was published for gettext-converter (npm) Aug 20, 2026
Dremig Credited to Dremig
Wagtail: Improper restriction handling on Page translation API endpoint Moderate
GHSA-jm5p-837g-rv8g was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman and tinyb0y tinyb0y tinyb0y
Wagtail: Improper permission handling when copying snippets Moderate
GHSA-x5cx-w6p2-mxf2 was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman and tinyb0y tinyb0y tinyb0y
Wagtail: Improper restriction handling on descendant collections in Documents and Images API Moderate
GHSA-c2xx-cjmh-9q8f was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, RealOrangeOne, and thientd RealOrangeOne RealOrangeOne
thientd thientd
Wagtail: Identification of documents by SHA1 hash Low
GHSA-92hv-j533-69wc was published for wagtail (pip) Aug 20, 2026
gasman Credited to gasman, unknownhad, and RealOrangeOne unknownhad unknownhad
RealOrangeOne RealOrangeOne
Winter: Reflected XSS through the search query parameter in the backend Table widget Moderate
GHSA-hq84-x37p-j6q5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
ProTip! Advisories are also available from the GraphQL API