Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,900 advisories

Loading
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem High
CVE-2026-40987 was published for org.springframework.integration:spring-integration-file (Maven) Jun 11, 2026
julianladisch Credited to julianladisch, oleg-andreev-check24, and ChristianAchatz oleg-andreev-check24 oleg-andreev-check24
ChristianAchatz ChristianAchatz
fastjson has a remote code execution (RCE) vulnerability Critical
CVE-2026-16723 was published for com.alibaba:fastjson (Maven) Jul 23, 2026
dor-hayun Credited to dor-hayun, AnvithaCDhanekula, and timtebeek AnvithaCDhanekula AnvithaCDhanekula
timtebeek timtebeek
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
jsoup: Cleaner may expose markup with custom raw-text elements Moderate
CVE-2026-71497 was published for org.jsoup:jsoup (Maven) Aug 6, 2026
quitbug Credited to quitbug and jhy jhy jhy
Apache cxf-core: No restriction on attachment headers per message High
CVE-2026-50645 was published for org.apache.cxf:cxf-core (Maven) Jun 12, 2026
julianladisch Credited to julianladisch and coheigea coheigea coheigea
Spring Framework Server-Side Request Forgery via UriComponentsBuilder Moderate
CVE-2026-41854 was published for org.springframework:spring-web (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer HTTP server instrumentations DoS High
CVE-2026-40984 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
Micrometer gRPC server instrumentation DoS High
CVE-2026-40983 was published for io.micrometer:micrometer-core (Maven) Jun 9, 2026
julianladisch Credited to julianladisch
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) High
CVE-2026-54513 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types High
CVE-2026-44795 was published for io.spinnaker.orca:orca-core (Maven) Jun 22, 2026
connorshea Credited to connorshea
Keycloak has an Authentication Bypass by Primary Weakness Moderate
CVE-2026-9798 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
Keycloak Services has Improper Validation of Consistency within Input Moderate
CVE-2026-9689 was published for org.keycloak:keycloak-services (Maven) May 27, 2026
Keycloak has an Improper Verification of Cryptographic Signature issue Moderate
CVE-2026-9793 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion Moderate
CVE-2026-48043 was published for io.netty:netty-codec-http2 (Maven) Jun 11, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion High
CVE-2026-48059 was published for io.netty:netty-codec-haproxy (Maven) Jun 11, 2026
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator High
CVE-2026-48006 was published for io.netty:netty-codec-redis (Maven) Jun 11, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title High
CVE-2025-66024 was published for org.xwiki.contrib.blog:application-blog-ui (Maven) Mar 4, 2026
lukasz-rybak Credited to lukasz-rybak and sealbenb sealbenb sealbenb
CometVisu Backend for openHAB affected by SSRF/XSS High
CVE-2024-42467 was published for org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven) Aug 9, 2024
p- Credited to p-, peuter, and sealbenb peuter peuter
sealbenb sealbenb
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service High
CVE-2026-45799 was published for com.squareup.wire:wire-runtime (Maven) May 19, 2026
TrekLaps Credited to TrekLaps and tal-sealsecurity tal-sealsecurity tal-sealsecurity
json-smart Uncontrolled Recursion vulnerability High
CVE-2023-1370 was published for net.minidev:json-smart (Maven) Mar 23, 2023
oswaldobapvicjr Credited to oswaldobapvicjr
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
Netty has Insufficient Bailiwick Validation for NS Records High
CVE-2026-47691 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records High
CVE-2026-45674 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem and mprins mprins mprins
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback Critical
CVE-2026-62379 was published for org.openidentityplatform.openam:openam-core (Maven) Jul 24, 2026
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
ProTip! Advisories are also available from the GraphQL API