Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,562 advisories

Loading
Keras: tar extraction permits symlink-based path traversal Low
CVE-2026-12482 was published for keras (pip) Jul 14, 2026
Django: signed cookies are vulnerable to salt namespace collisions Low
CVE-2026-6873 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
cgurnik Credited to cgurnik and hahwul hahwul hahwul
Django: has_vary_header may expose cached responses when Vary values contain whitespace Low
CVE-2026-48587 was published for django (pip) Jun 3, 2026
cgurnik Credited to cgurnik
cgurnik Credited to cgurnik
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read Low
CVE-2026-56394 was published for craftcms/cms (Composer) Jul 9, 2026
GCXWLP Credited to GCXWLP
GCXWLP Credited to GCXWLP
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Low
CVE-2026-56393 was published for craftcms/cms (Composer) Mar 3, 2026
mHe4am Credited to mHe4am
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Low
CVE-2026-56381 was published for craftcms/cms (Composer) Mar 11, 2026
mHe4am Credited to mHe4am
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
GHSA-7hxc-f267-h5q7 was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Low
CVE-2026-56383 was published for craftcms/cms (Composer) Feb 25, 2026
mHe4am Credited to mHe4am
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Contao crawler leaks auth credentials to external hosts Low
CVE-2026-55824 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse Low
CVE-2026-6733 was published for undici (npm) Jun 19, 2026
mcollina Credited to mcollina, UlisesGascon, and EchoTydes UlisesGascon UlisesGascon
EchoTydes EchoTydes
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote Low
GHSA-945v-v9p3-v5xw was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Verbose Stack Trace Disclosure in RC API Error Responses Low
GHSA-gwfq-86j8-7qhv was published for github.com/rclone/rclone (Go) Aug 5, 2026
SnailSploit Credited to SnailSploit and ncw ncw ncw
Electron: Cross-origin iframe can position native autofill popup Low
CVE-2026-70600 was published for electron (npm) Aug 5, 2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size Low
CVE-2026-70598 was published for electron (npm) Aug 5, 2026
GabrielGomesAL Credited to GabrielGomesAL and Classic298 Classic298 Classic298
ProTip! Advisories are also available from the GraphQL API