Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

30 advisories

Loading
alexandre-daubois Credited to alexandre-daubois
async-tar PAX extension-header desync enables tar entry/content smuggling Moderate
CVE-2026-53600 was published for async-tar (Rust) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
tar has a PAX header desynchronization issue Moderate
GHSA-3pv8-6f4r-ffg2 was published for tar (Rust) May 29, 2026
woodruffw Credited to woodruffw
astral-tokio-tar has a PAX Header Desynchronization issue Moderate
GHSA-3cv2-h65g-fgmm was published for astral-tokio-tar (Rust) May 29, 2026
woodruffw Credited to woodruffw
tar-rs incorrectly ignores PAX size headers if header size is nonzero Moderate
CVE-2026-33055 was published for tar (Rust) Mar 20, 2026
xokdvium Credited to xokdvium, woodruffw, 0xnaka-hax, and 0xNakah woodruffw woodruffw
0xnaka-hax 0xnaka-hax 0xNakah 0xNakah
TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function Moderate
GHSA-9m65-766c-r333 was published for @tanstack/start-server-core (npm) May 14, 2026
mufeedvh Credited to mufeedvh
astral-tokio-tar is Vulnerable to PAX Header Desynchronization Moderate
GHSA-fp55-jw48-c537 was published for astral-tokio-tar (Rust) May 6, 2026
LawnGnome Credited to LawnGnome and woodruffw woodruffw woodruffw
Roundcube Webmail: Incorrect password comparison in the password plugin Moderate
CVE-2026-35541 was published for roundcube/roundcubemail (Composer) Apr 3, 2026
DynFuture Drop Can Construct a Dangling Reference Moderate
GHSA-j3w3-p6mr-3hrh was published for dyn-future (Rust) Apr 4, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value Moderate
CVE-2026-34595 was published for parse-server (npm) Apr 1, 2026
bugbunny-research Credited to bugbunny-research and mtrezza mtrezza mtrezza
CPU exhaustion in SvelteKit remote form deserialization (experimental only) Moderate
GHSA-88qp-p4qg-rqm6 was published for @sveltejs/kit (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
jsonwebtoken has Type Confusion that leads to potential authorization bypass Moderate
CVE-2026-25537 was published for jsonwebtoken (Rust) Feb 3, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars Moderate
CVE-2025-61911 was published for python-ldap (pip) Oct 10, 2025
lukas-eu Credited to lukas-eu
@digitalocean/do-markdownit has Type Confusion vulnerability Moderate
CVE-2025-59717 was published for @digitalocean/do-markdownit (npm) Sep 19, 2025
cai0duque Credited to cai0duque
Prototype Pollution in node-jsonpointer Moderate
CVE-2021-23807 was published for jsonpointer (npm) Nov 8, 2021
Undefined behaviour in `kvm_ioctls::ioctls::vm::VmFd::create_device` Moderate
GHSA-3qx8-rv27-j6gp was published for kvm-ioctls (Rust) Dec 23, 2024
Jenkins item creation restriction bypass vulnerability Moderate
CVE-2024-47804 was published for org.jenkins-ci.main:jenkins-core (Maven) Oct 2, 2024
Wrong type for `Linker`-define functions when used across two `Engine`s Moderate
CVE-2021-39219 was published for wasmtime (pip) Sep 20, 2021
alexcrichton Credited to alexcrichton
`CHECK`-failures in binary ops in Tensorflow Moderate
CVE-2022-23583 was published for tensorflow (pip) Feb 10, 2022
Type confusion in mpath Moderate
CVE-2021-23438 was published for mpath (npm) Sep 2, 2021
Cross-site Scripting in edge.js Moderate
CVE-2021-23443 was published for edge.js (npm) Sep 22, 2021
Prototype Pollution in object-path Moderate
CVE-2021-23434 was published for object-path (npm) Sep 1, 2021
Prototype Pollution in dotty Moderate
CVE-2021-23624 was published for dotty (npm) Nov 8, 2021
Prototype Pollution in json-ptr Moderate
CVE-2021-23509 was published for json-ptr (npm) Nov 8, 2021
Cross-site Scripting in teddy Moderate
CVE-2021-23447 was published for teddy (npm) Oct 12, 2021
ProTip! Advisories are also available from the GraphQL API