Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,937 advisories

Loading
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service High
CVE-2026-77633 was published for github.com/cloudreve/Cloudreve/v4 (Go) Sep 22, 2026
newugly Credited to newugly
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) High
CVE-2026-94462 was published for spree_api (RubyGems) Sep 22, 2026
laijunyue Credited to laijunyue
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability High
CVE-2026-76819 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
akues-an Credited to akues-an
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API High
CVE-2026-62371 was published for github.com/kubeedge/kubeedge (Go) Sep 22, 2026
DoisLONG Credited to DoisLONG, liyuerich, and kevin-wangzefeng liyuerich liyuerich
kevin-wangzefeng kevin-wangzefeng
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join High
CVE-2026-62369 was published for github.com/kubeedge/kubeedge (Go) Sep 22, 2026
DoisLONG Credited to DoisLONG and kevin-wangzefeng kevin-wangzefeng kevin-wangzefeng
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters High
CVE-2026-71543 was published for github.com/openbao/openbao (Go) Sep 22, 2026
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes High
CVE-2026-62182 was published for github.com/kubeedge/kubeedge (Go) Sep 22, 2026
DoisLONG Credited to DoisLONG and kevin-wangzefeng kevin-wangzefeng kevin-wangzefeng
Unleash: Missing await on permission check + cross-project IDOR in admin API High
CVE-2026-77426 was published for unleash-server (npm) Sep 22, 2026
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() High
CVE-2026-77258 was published for mcp-atlassian (pip) Sep 22, 2026
junbyjun1238 Credited to junbyjun1238
MCP Atlassian: SSRF Protection Bypass High
CVE-2026-77274 was published for mcp-atlassian (pip) Sep 22, 2026
RacerZ-fighting Credited to RacerZ-fighting
b-hermes Credited to b-hermes
mcp-atlassian has an incomplete SSRF remediation High
CVE-2026-77267 was published for mcp-atlassian (pip) Sep 22, 2026
romain-deperne Credited to romain-deperne
rushitgit Credited to rushitgit
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches High
CVE-2026-77261 was published for mcp-atlassian (pip) Sep 22, 2026
hewei-gikaku Credited to hewei-gikaku
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths High
CVE-2026-77257 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass High
CVE-2026-77243 was published for mcp-atlassian (pip) Sep 22, 2026
0xmagic0 Credited to 0xmagic0
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue High
CVE-2026-77255 was published for mcp-atlassian (pip) Sep 22, 2026
aurelienp-alt Credited to aurelienp-alt
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files High
CVE-2026-77253 was published for mcp-atlassian (pip) Sep 22, 2026
sondt99 Credited to sondt99
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path High
CVE-2026-77246 was published for mcp-atlassian (pip) Sep 22, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
ProTip! Advisories are also available from the GraphQL API