Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,957 advisories

Loading
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module Low
CVE-2026-57232 was published for contao/contao (Composer) Sep 24, 2026
Para213 Credited to Para213
social-auth-core has a Session Fixation issue Moderate
CVE-2026-57179 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing High
CVE-2026-57178 was published for social-auth-core (pip) Sep 24, 2026
lalalala5678 Credited to lalalala5678 and nijel nijel nijel
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend Moderate
CVE-2026-57177 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend Moderate
CVE-2026-57176 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
social-auth-core has an Improper Authentication issue Moderate
CVE-2026-57175 was published for social-auth-core (pip) Sep 24, 2026
mauriceng98 Credited to mauriceng98 and nijel nijel nijel
Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets Moderate
CVE-2026-55736 was published for ash (Erlang) Sep 24, 2026
alfieV Credited to alfieV, zachdaniel, and maennchen zachdaniel zachdaniel
maennchen maennchen
Yanchon918s Credited to Yanchon918s
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) High
CVE-2026-57170 was published for compliance-trestle (pip) Sep 24, 2026
clzoom Credited to clzoom
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint) High
CVE-2026-59723 was published for cline (npm) Sep 24, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
zbateson/mail-mime-parser has CRLF header injection via attachment filename High
CVE-2026-61815 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
iliaal Credited to iliaal
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME High
CVE-2026-61816 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input Moderate
CVE-2026-59980 was published for hpack (pip) Sep 24, 2026
tawAsh1 Credited to tawAsh1
@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata High
CVE-2026-61782 was published for @rsdoctor/rspack-plugin (npm) Sep 24, 2026
EQSTLab Credited to EQSTLab
Podman: Malformed Image can trick podman run into leaking host environment variables into the container High
CVE-2026-57231 was published for github.com/containers/podman (Go) Sep 24, 2026
unknownhad Credited to unknownhad
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces Moderate
CVE-2026-56742 was published for github.com/cilium/cilium (Go) Sep 24, 2026
mhofstetter Credited to mhofstetter and galanko galanko galanko
@bytebase/dbhub's read-only mode does not prevent database writes High
CVE-2026-61788 was published for @bytebase/dbhub (npm) Sep 24, 2026
ixNyf Credited to ixNyf
DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution Critical
CVE-2026-61742 was published for @bytebase/dbhub (npm) Sep 24, 2026
junbyjun1238 Credited to junbyjun1238 and avishaigonen-pluto avishaigonen-pluto avishaigonen-pluto
http4s-scala-xml has an XML External Entity (XXE) processing issue Critical
CVE-2026-61741 was published for org.http4s:http4s-scala-xml_2.12 (Maven) Sep 24, 2026
rossabaker Credited to rossabaker and samspills samspills samspills
xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS Moderate
CVE-2026-61784 was published for xhtml-purifier (npm) Sep 24, 2026
EchoTydes Credited to EchoTydes
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion High
CVE-2026-56738 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
DomainXTech Credited to DomainXTech
phpMyFAQ's two-factor authentication login bypasses the password factor High
CVE-2026-56737 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
waseem-cve Credited to waseem-cve
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission High
CVE-2026-56736 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
JosanGeorge Credited to JosanGeorge
langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs High
GHSA-g28h-2cmm-rj9x was published for langchain-nvidia-ai-endpoints (pip) Sep 24, 2026
ProTip! Advisories are also available from the GraphQL API