Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,785 advisories

Loading
SIPGO: DoS via unvalidated Content-Length in the stream parser High
CVE-2026-58268 was published for github.com/emiago/sipgo (Go) Sep 22, 2026
arkark Credited to arkark
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes High
CVE-2026-63116 was published for @deepstream/server (npm) Sep 22, 2026
manus-use Credited to manus-use
usama0x01 Credited to usama0x01
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` Moderate
CVE-2026-62866 was published for github.com/tomwright/dasel/v3 (Go) Sep 22, 2026
vnykmshr Credited to vnykmshr
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS Moderate
CVE-2026-59168 was published for github.com/tomwright/dasel/v3 (Go) Sep 22, 2026
vmfunc Credited to vmfunc
OpenCVE: Server-Side Request Forgery (SSRF) in notifications Moderate
CVE-2026-62282 was published for opencve (pip) Sep 22, 2026
geo-chen Credited to geo-chen
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry High
CVE-2026-59991 was published for psd-tools (pip) Sep 22, 2026
joszamama Credited to joszamama
microsandbox: Secret values exposed in world-readable process arguments Moderate
CVE-2026-61670 was published for microsandbox (Rust) Sep 22, 2026
nopcorn Credited to nopcorn
9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header Moderate
CVE-2026-56682 was published for 9router (npm) Sep 22, 2026
b401t Credited to b401t
9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header High
CVE-2026-56681 was published for 9router (npm) Sep 22, 2026
b401t Credited to b401t
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509 Moderate
CVE-2026-61612 was published for @aborruso/ckan-mcp-server (npm) Sep 22, 2026
EchoSkorJjj Credited to EchoSkorJjj
456789TZ Credited to 456789TZ and johaven johaven johaven
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` Moderate
CVE-2026-58270 was published for @sync-in/server (npm) Sep 22, 2026
SakusenSec Credited to SakusenSec and johaven johaven johaven
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` High
CVE-2026-58269 was published for @sync-in/server (npm) Sep 22, 2026
SakusenSec Credited to SakusenSec and johaven johaven johaven
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` Moderate
CVE-2026-58271 was published for @sync-in/server (npm) Sep 22, 2026
SakusenSec Credited to SakusenSec and johaven johaven johaven
mcfly-zzh Credited to mcfly-zzh
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition High
CVE-2026-61628 was published for github.com/lucasdillmann/nginx-ignition (Go) Sep 21, 2026
tikket1 Credited to tikket1 and lucasdillmann lucasdillmann lucasdillmann
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware High
CVE-2026-61629 was published for github.com/lucasdillmann/nginx-ignition (Go) Sep 21, 2026
tonghuaroot Credited to tonghuaroot and lucasdillmann lucasdillmann lucasdillmann
nginx ignition has TOTP Reuse During Validity Window Moderate
CVE-2026-61630 was published for github.com/lucasdillmann/nginx-ignition (Go) Sep 21, 2026
alp1n3-dev Credited to alp1n3-dev and lucasdillmann lucasdillmann lucasdillmann
k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers Moderate
GHSA-jhjp-4c2q-xmx4 was published for github.com/falcosecurity/plugins/plugins/k8saudit (Go) Sep 21, 2026
kanywst Credited to kanywst, leogr, ekoops, and c2ndev leogr leogr
ekoops ekoops c2ndev c2ndev
manop55555 Credited to manop55555
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: MCP Registry API readable without authentication Moderate
GHSA-pr6h-vr44-xq8j was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion High
GHSA-xwmw-prc4-v3cr was published for github.com/obot-platform/obot (Go) Sep 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade) Moderate
CVE-2026-71537 was published for paymenter/paymenter (Composer) Sep 18, 2026
Pig-Tail Credited to Pig-Tail and CorwinDev CorwinDev CorwinDev
ProTip! Advisories are also available from the GraphQL API