Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

133,099 advisories

Loading
Weintek cMT3092X HMI stores user account passwords in plaintext. High Unreviewed
CVE-2026-61886 was published Jul 25, 2026
An attacker can modify data that should be restricted to read‑only access. High Unreviewed
CVE-2026-60135 was published Jul 25, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
GHSA-6vch-q96h-7gc3 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages() High
CVE-2026-16796 was published for bedrock-agentcore (pip) Jul 24, 2026
MrCloudSec Credited to MrCloudSec
etcd: Watch API authorization bypass via open-ended range requests High
GHSA-xg4h-6gfc-h4m8 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
libp2p: yamux connection DoS via oversized data frame High
GHSA-hmj8-5xmh-5573 was published for libp2p (pip) Jul 24, 2026
tahaafarooq Credited to tahaafarooq
Oh My Posh: Arbitrary command execution via template injection in the path segment High
GHSA-6xj8-qv9j-xcjq was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure High
CVE-2026-16584 was published for awslabs.aws-api-mcp-server (pip) Jul 24, 2026
arnewouters Credited to arnewouters
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
GHSA-95cv-r8x4-vh75 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server High
GHSA-7ppr-r889-mcf2 was published for org.http4s:http4s-blaze-server_2.12 (Maven) Jul 24, 2026
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) High
GHSA-46q4-43ph-c6fr was published for org.http4s:blaze-http_2.12 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser High
GHSA-mhvj-jhpq-885v was published for org.http4s:blaze-http_2.13 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover High
GHSA-cmwh-g2h8-c222 was published for poweradmin/poweradmin (Composer) Jul 24, 2026
William957-web Credited to William957-web
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account High
GHSA-h4hf-v6w5-897x was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
ProTip! Advisories are also available from the GraphQL API