Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,868 advisories

Loading
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak Critical
GHSA-mqhr-6j6h-74p5 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored Moderate
CVE-2026-62323 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified Critical
GHSA-hp6v-6jw7-gv2f was published for @budibase/server (npm) Jul 24, 2026
freeman-bb Credited to freeman-bb
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution High
GHSA-xg5g-26x8-cvf4 was published for @budibase/server (npm) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
DavidCarliez Credited to DavidCarliez
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile High
GHSA-ppr4-5f46-j9c6 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
Budibase: SQL Injection via `multipleStatements: true` Critical
GHSA-q6x4-v3qx-85qw was published for @budibase/server (npm) Jul 24, 2026
kaimandalic Credited to kaimandalic
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users Moderate
GHSA-fcrw-f7gg-6g9f was published for @budibase/server (npm) Jul 24, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings Moderate
GHSA-4qcj-m5wp-jmf4 was published for @budibase/server (npm) Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
GHSA-j9fc-w3mr-x6mv was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
react-server-dom: Denial of Service in Server Functions High
CVE-2026-44907 was published for react-server-dom-parcel (npm) Jul 24, 2026
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback Critical
CVE-2026-62379 was published for org.openidentityplatform.openam:openam-core (Maven) Jul 24, 2026
manus-use Credited to manus-use
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass Critical
CVE-2026-62263 was published for org.openidentityplatform.openam:openam-auth-webauthn (Maven) Jul 24, 2026
Pig-Tail Credited to Pig-Tail, MarkLee131, baradika, manus-use, and tonghuaroot MarkLee131 MarkLee131
baradika baradika manus-use manus-use tonghuaroot tonghuaroot
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal High
CVE-2026-59221 was published for open-webui (pip) Jul 24, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
Open WebUI: Arena task endpoints can bypass underlying model access controls Moderate
CVE-2026-59225 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Moderate
CVE-2026-59212 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
smoke-wolf Credited to smoke-wolf, rexpository, and Classic298 rexpository rexpository
Classic298 Classic298
addcontent Credited to addcontent and Classic298 Classic298 Classic298
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules Moderate
CVE-2026-57497 was published for github.com/quic-go/webtransport-go (Go) Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials High
CVE-2026-55502 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
riodrwn Credited to riodrwn
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails Moderate
CVE-2026-55496 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
ProTip! Advisories are also available from the GraphQL API