Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

14,775 advisories

Loading
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller Moderate
GHSA-8q49-2h5h-434x was published for @frontmcp/adapters (npm) Jul 24, 2026
EchoSkorJjj Credited to EchoSkorJjj and frontegg-david frontegg-david frontegg-david
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema Moderate
GHSA-jpcw-4wr7-c3vq was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
matiasinsaurralde Credited to matiasinsaurralde
Quasar: Prototype pollution in the extend() utility Moderate
GHSA-3r53-75j5-3g7j was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data Moderate
GHSA-fwjx-9p69-h25h was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
GHSA-q53c-4prm-w95q was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Path disclosure on Unix with Zsh Moderate
GHSA-6v4m-fw66-8r4x was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
GHSA-86cx-wwf4-phq4 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
swift-nio-http2: Missing CR/LF/NUL validation in header values Moderate
CVE-2026-64785 was published for swift-nio-http2 (Swift) Jul 24, 2026
sour-exploit Credited to sour-exploit
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources Moderate
GHSA-c534-2w9c-x7fm was published for github.com/zxh326/kite (Go) Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation Moderate
GHSA-hfhx-w8p8-4hc7 was published for @budibase/server (npm) Jul 24, 2026
oduoke567 Credited to oduoke567
Budibase: Account Enumeration via Login Lockout Response Differential Moderate
GHSA-cr7p-cr3q-h5cm was published for @budibase/server (npm) Jul 24, 2026
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders Moderate
GHSA-gh4h-34gr-87r7 was published for @budibase/server (npm) Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored Moderate
CVE-2026-62323 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users Moderate
GHSA-fcrw-f7gg-6g9f was published for @budibase/server (npm) Jul 24, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings Moderate
GHSA-4qcj-m5wp-jmf4 was published for @budibase/server (npm) Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
Open WebUI: Arena task endpoints can bypass underlying model access controls Moderate
CVE-2026-59225 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Moderate
CVE-2026-59212 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
addcontent Credited to addcontent and Classic298 Classic298 Classic298
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules Moderate
CVE-2026-57497 was published for github.com/quic-go/webtransport-go (Go) Jul 24, 2026
riodrwn Credited to riodrwn
ProTip! Advisories are also available from the GraphQL API