Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,254 advisories

Loading
Mirr2 Credited to Mirr2
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure High
CVE-2026-70471 was published for flowise (npm) Aug 4, 2026
EaEa0001 Credited to EaEa0001
leoelsolh Credited to leoelsolh
Aviral2642 Credited to Aviral2642
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses High
CVE-2026-69257 was published for flowise (npm) Aug 4, 2026
feiyang666 Credited to feiyang666
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration High
CVE-2026-69250 was published for flowise (npm) Aug 4, 2026
b-hermes Credited to b-hermes
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building High
CVE-2026-69249 was published for cryptography (pip) Aug 3, 2026
sjudson Credited to sjudson and woodruffw woodruffw woodruffw
X1AOxiang Credited to X1AOxiang
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
agners Credited to agners and bdraco bdraco bdraco
mcollina Credited to mcollina, UlisesGascon, and h0rk1p UlisesGascon UlisesGascon
h0rk1p h0rk1p
fast-uri vulnerable to host confusion via backslash authority introducer High
CVE-2026-18446 was published for fast-uri (npm) Aug 3, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Socket.IO: Zero-attachment Memory Exhaustion High
CVE-2026-69185 was published for socket.io-parser (npm) Aug 3, 2026
aretekzs Credited to aretekzs, mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk mauriceng98 mauriceng98
Zyy0530 Zyy0530 Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation High
CVE-2026-69152 was published for brace-expansion (npm) Aug 3, 2026
G-Rath Credited to G-Rath and katzj katzj katzj
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes High
CVE-2026-69151 was published for @angular/compiler (npm) Aug 3, 2026
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) High
CVE-2026-69149 was published for @angular/platform-server (npm) Aug 3, 2026
SkyZeroZx Credited to SkyZeroZx and alan-agius4 alan-agius4 alan-agius4
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers High
GHSA-mqq9-gxg5-m58g was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved High
GHSA-mjrx-74jh-7xgw was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
GHSA-7qf5-7ppr-87v8 was published for github.com/traefik/traefik/v3 (Go) Aug 1, 2026 withdrawn
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
ProTip! Advisories are also available from the GraphQL API