Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,868 advisories

Loading
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password Critical
GHSA-f25v-x6vr-962g was published for pheditor/pheditor (Composer) Jul 24, 2026
sermikr0 Credited to sermikr0
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr
swift-nio-http2: Missing CR/LF/NUL validation in header values Moderate
CVE-2026-64785 was published for swift-nio-http2 (Swift) Jul 24, 2026
sour-exploit Credited to sour-exploit
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
GHSA-vh45-f885-3848 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review High
GHSA-47w6-gwp4-w6vc was published for vantage6 (pip) Jul 24, 2026
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics Low
GHSA-2625-rw7m-5q5x was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic Moderate
GHSA-qqc3-94qv-7fw3 was published for hubuum_client (Rust) Jul 24, 2026
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects Moderate
GHSA-f45q-w629-wr25 was published for hubuum_client (Rust) Jul 24, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
GHSA-26gq-p25f-99cp was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
GHSA-g5vv-q72c-7j78 was published for @anephenix/hub (npm) Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources Moderate
GHSA-c534-2w9c-x7fm was published for github.com/zxh326/kite (Go) Jul 24, 2026
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
GHSA-p279-2cqp-84jg was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
anir0y Credited to anir0y, manus-use, sermikr0, adamyordan, Pig-Tail, tonghuaroot, and alimony manus-use manus-use
sermikr0 sermikr0 adamyordan adamyordan Pig-Tail Pig-Tail tonghuaroot tonghuaroot alimony alimony
alimony Credited to alimony
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation Moderate
GHSA-hfhx-w8p8-4hc7 was published for @budibase/server (npm) Jul 24, 2026
oduoke567 Credited to oduoke567
Budibase: SSRF via DNS rebinding in the REST datasource integration High
GHSA-v42f-v8xc-j435 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Budibase: Account Enumeration via Login Lockout Response Differential Moderate
GHSA-cr7p-cr3q-h5cm was published for @budibase/server (npm) Jul 24, 2026
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector High
GHSA-2xgg-r2wc-c5r2 was published for @budibase/server (npm) Jul 24, 2026
mhr-isham Credited to mhr-isham
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution High
GHSA-qw6m-8fw2-2v64 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders Moderate
GHSA-gh4h-34gr-87r7 was published for @budibase/server (npm) Jul 24, 2026
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint High
GHSA-hr66-5mqr-8mpx was published for @budibase/server (npm) Jul 24, 2026
sondt99 Credited to sondt99
ProTip! Advisories are also available from the GraphQL API