Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,275 advisories

Loading
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem High
CVE-2026-40987 was published for org.springframework.integration:spring-integration-file (Maven) Jun 11, 2026
julianladisch Credited to julianladisch, oleg-andreev-check24, and ChristianAchatz oleg-andreev-check24 oleg-andreev-check24
ChristianAchatz ChristianAchatz
Apache cxf-core: No restriction on attachment headers per message High
CVE-2026-50645 was published for org.apache.cxf:cxf-core (Maven) Jun 12, 2026
julianladisch Credited to julianladisch and coheigea coheigea coheigea
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) High
CVE-2026-54513 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types High
CVE-2026-44795 was published for io.spinnaker.orca:orca-core (Maven) Jun 22, 2026
connorshea Credited to connorshea
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion High
CVE-2026-48059 was published for io.netty:netty-codec-haproxy (Maven) Jun 11, 2026
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator High
CVE-2026-48006 was published for io.netty:netty-codec-redis (Maven) Jun 11, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title High
CVE-2025-66024 was published for org.xwiki.contrib.blog:application-blog-ui (Maven) Mar 4, 2026
lukasz-rybak Credited to lukasz-rybak and sealbenb sealbenb sealbenb
CometVisu Backend for openHAB affected by SSRF/XSS High
CVE-2024-42467 was published for org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven) Aug 9, 2024
p- Credited to p-, peuter, and sealbenb peuter peuter
sealbenb sealbenb
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service High
CVE-2026-45799 was published for com.squareup.wire:wire-runtime (Maven) May 19, 2026
TrekLaps Credited to TrekLaps and tal-sealsecurity tal-sealsecurity tal-sealsecurity
json-smart Uncontrolled Recursion vulnerability High
CVE-2023-1370 was published for net.minidev:json-smart (Maven) Mar 23, 2023
oswaldobapvicjr Credited to oswaldobapvicjr
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
Netty has Insufficient Bailiwick Validation for NS Records High
CVE-2026-47691 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records High
CVE-2026-45674 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
Spring Data: Unbounded property-path cache keyed by externally-supplied path string High
CVE-2026-41695 was published for org.springframework.data:spring-data-commons (Maven) Jul 31, 2026
Spring Framework Algorithmic Denial of Service via SpEL Expressions High
CVE-2026-41850 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Spring Framework Cross-site Scripting via JavaScriptUtils High
CVE-2026-41845 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions High
CVE-2026-41849 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux High
CVE-2026-41842 was published for org.springframework:spring-webflux (Maven) Jun 9, 2026
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
Spring LDAP has Authentication Bypass with Empty Password High
CVE-2026-41720 was published for org.springframework.ldap:spring-ldap-core (Maven) Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching High
CVE-2026-41007 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
ProTip! Advisories are also available from the GraphQL API