Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,272 advisories

Loading
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types High
CVE-2026-44795 was published for io.spinnaker.orca:orca-core (Maven) Jun 22, 2026
connorshea Credited to connorshea
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator High
CVE-2026-48006 was published for io.netty:netty-codec-redis (Maven) Jun 11, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion High
CVE-2026-48059 was published for io.netty:netty-codec-haproxy (Maven) Jun 11, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title High
CVE-2025-66024 was published for org.xwiki.contrib.blog:application-blog-ui (Maven) Mar 4, 2026
lukasz-rybak Credited to lukasz-rybak and sealbenb sealbenb sealbenb
CometVisu Backend for openHAB affected by SSRF/XSS High
CVE-2024-42467 was published for org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven) Aug 9, 2024
p- Credited to p-, peuter, and sealbenb peuter peuter
sealbenb sealbenb
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service High
CVE-2026-45799 was published for com.squareup.wire:wire-runtime (Maven) May 19, 2026
TrekLaps Credited to TrekLaps and tal-sealsecurity tal-sealsecurity tal-sealsecurity
json-smart Uncontrolled Recursion vulnerability High
CVE-2023-1370 was published for net.minidev:json-smart (Maven) Mar 23, 2023
oswaldobapvicjr Credited to oswaldobapvicjr
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
Netty has Insufficient Bailiwick Validation for NS Records High
CVE-2026-47691 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records High
CVE-2026-45674 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
Spring Data: Unbounded property-path cache keyed by externally-supplied path string High
CVE-2026-41695 was published for org.springframework.data:spring-data-commons (Maven) Jul 31, 2026
Spring Framework Algorithmic Denial of Service via SpEL Expressions High
CVE-2026-41850 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Spring Framework Cross-site Scripting via JavaScriptUtils High
CVE-2026-41845 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions High
CVE-2026-41849 was published for org.springframework:spring-expression (Maven) Jun 9, 2026
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux High
CVE-2026-41842 was published for org.springframework:spring-webflux (Maven) Jun 9, 2026
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) High
CVE-2026-54513 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
Spring LDAP has Authentication Bypass with Empty Password High
CVE-2026-41720 was published for org.springframework.ldap:spring-ldap-core (Maven) Jun 9, 2026
Spring HATEOAS heap exhaustion through unbounded internal caching High
CVE-2026-41007 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration High
CVE-2026-41006 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
veraPDF Validation XXE via Rich Text High
CVE-2026-54078 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Validation XXE via XFA High
CVE-2026-54079 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
wodzen Credited to wodzen
Quarkus has Authentication/Authorization bypasses High
CVE-2026-39852 was published for io.quarkus:quarkus-vertx-http (Maven) May 4, 2026
p- Credited to p-
ProTip! Advisories are also available from the GraphQL API