Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,434 advisories

Loading
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions Moderate
CVE-2026-59941 was published for dompdf/dompdf (Composer) Jul 22, 2026
riodrwn Credited to riodrwn
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI Moderate
CVE-2026-56722 was published for dompdf/dompdf (Composer) Jul 22, 2026
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation Moderate
CVE-2026-59882 was published for guzzlehttp/psr7 (Composer) Jul 21, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: URI fragments disclosed in redirect Referer headers Moderate
GHSA-h95v-h523-3mw8 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Host-only cookie scope is not preserved Moderate
GHSA-wm3w-8rrp-j577 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-f283-ghqc-fg79 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Cookie Disclosure and Injection via IP-Address Domains Moderate
CVE-2026-59883 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files Moderate
CVE-2026-59946 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) Moderate
CVE-2026-59947 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-94pj-82f3-465w was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration Moderate
GHSA-cvpc-hccg-wmw4 was published for verbb/formie (Composer) Jul 17, 2026
chaitanyagarware Credited to chaitanyagarware
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files Moderate
GHSA-xg43-5579-qw6v was published for adawolfa/isdoc (Composer) Jul 15, 2026
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs Moderate
CVE-2026-52883 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
byteoverride Credited to byteoverride and dregad dregad dregad
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters Moderate
CVE-2026-52882 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dregad Credited to dregad
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail Moderate
CVE-2026-50552 was published for phanan/koel (Composer) Jul 15, 2026
Yunkaiwjs Credited to Yunkaiwjs
Koel has SSRF through Authenticated Subsonic podcast feed URLs Moderate
GHSA-8q6q-m837-fv64 was published for phanan/koel (Composer) Jul 15, 2026
DavidCarliez Credited to DavidCarliez
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation Moderate
CVE-2026-54492 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
MantisBT: REST API unauthorized Issue status change Moderate
CVE-2026-49280 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dregad Credited to dregad and mamdouhmahfouz mamdouhmahfouz mamdouhmahfouz
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter Moderate
CVE-2026-50157 was published for auth0/symfony (Composer) Jul 14, 2026
Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access Moderate
CVE-2026-52828 was published for kimai/kimai (Composer) Jul 14, 2026
AzureADTrent Credited to AzureADTrent
Mitchell45 Credited to Mitchell45
Mitchell45 Credited to Mitchell45
ProTip! Advisories are also available from the GraphQL API