Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,738 advisories

Loading
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
GHSA-g5vv-q72c-7j78 was published for @anephenix/hub (npm) Jul 24, 2026
Budibase: SSRF via DNS rebinding in the REST datasource integration High
GHSA-v42f-v8xc-j435 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector High
GHSA-2xgg-r2wc-c5r2 was published for @budibase/server (npm) Jul 24, 2026
mhr-isham Credited to mhr-isham
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution High
GHSA-qw6m-8fw2-2v64 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint High
GHSA-hr66-5mqr-8mpx was published for @budibase/server (npm) Jul 24, 2026
sondt99 Credited to sondt99
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution High
GHSA-xg5g-26x8-cvf4 was published for @budibase/server (npm) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
DavidCarliez Credited to DavidCarliez
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile High
GHSA-ppr4-5f46-j9c6 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
GHSA-j9fc-w3mr-x6mv was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
react-server-dom: Denial of Service in Server Functions High
CVE-2026-44907 was published for react-server-dom-parcel (npm) Jul 24, 2026
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution High
CVE-2026-55607 was published for @anthropic-ai/claude-code (npm) Jul 24, 2026
js-yaml: Exponential parsing time in flow collections leads to denial of service High
GHSA-pm4m-ph32-ghv5 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response High
GHSA-qwww-vcr4-c8h2 was published for react-router (npm) Jul 24, 2026
radityahack Credited to radityahack
@fastify/static vulnerable to route guard bypass via path traversal High
CVE-2026-15074 was published for @fastify/static (npm) Jul 24, 2026
imssm99 Credited to imssm99, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
alanturing881 Credited to alanturing881
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in High
GHSA-qq9h-g4jm-xgf3 was published for better-auth (npm) Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
React Router: Unauthenticated Denial of Service via Inefficient Route Matching High
CVE-2026-55685 was published for react-router (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce High
CVE-2026-55575 was published for liquidjs (npm) Jul 24, 2026
offset Credited to offset
Str1ckl4nd Credited to Str1ckl4nd
ProTip! Advisories are also available from the GraphQL API