Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

170 advisories

Loading
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization Moderate
CVE-2026-55766 was published for guzzlehttp/psr7 (Composer) Jun 19, 2026
iliaal Credited to iliaal
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding Moderate
CVE-2026-9679 was published for undici (npm) Jun 19, 2026
tndud042713 Credited to tndud042713, mcollina, KhafraDev, and UlisesGascon mcollina mcollina
KhafraDev KhafraDev UlisesGascon UlisesGascon
Kirby: Request header injection in `Http\Remote` Moderate
CVE-2026-50188 was published for getkirby/cms (Composer) Jun 18, 2026
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody` High
CVE-2026-55603 was published for http-proxy-middleware (npm) Jun 18, 2026
RamiAltai Credited to RamiAltai
Laravel Framework: CRLF injection in default email rule High
GHSA-5vg9-5847-vvmq was published for laravel/framework (Composer) Jun 17, 2026
OmarXtream Credited to OmarXtream
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server High
GHSA-7cx2-g3h9-382p was published for crawl4ai (pip) Jun 16, 2026
aiohttp: CRLF injection in multipart headers Low
CVE-2026-50269 was published for aiohttp (pip) Jun 15, 2026
tonghuaroot Credited to tonghuaroot and Dreamsorcerer Dreamsorcerer Dreamsorcerer
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection Moderate
GHSA-268h-hp4c-crq3 was published for nodemailer (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
form-data: CRLF injection in form-data via unescaped multipart field names and filenames High
CVE-2026-12143 was published for form-data (npm) Jun 15, 2026
yueyueL Credited to yueyueL
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator Moderate
CVE-2026-28970 was published for github.com/apple/swift-nio (Swift) Jun 12, 2026
kuranikaran Credited to kuranikaran and YLChen-007 YLChen-007 YLChen-007
guzzlehttp/psr7 has CRLF Injection via URI Host Component Moderate
CVE-2026-49214 was published for guzzlehttp/psr7 (Composer) Jun 11, 2026
edorian Credited to edorian
Net::IMAP: Command Injection via ID command argument Moderate
CVE-2026-47242 was published for net-imap (RubyGems) Jun 9, 2026
nevans Credited to nevans
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument Moderate
CVE-2026-47240 was published for net-imap (RubyGems) Jun 9, 2026
nevans Credited to nevans
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names Moderate
CVE-2026-45070 was published for symfony/mime (Composer) May 27, 2026
alexandre-daubois Credited to alexandre-daubois
ProTip! Advisories are also available from the GraphQL API