Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

535 advisories

Loading
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS) High
CVE-2026-49401 was published for deno (Rust) Jun 16, 2026
tomasilluminati Credited to tomasilluminati
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly High
GHSA-4w2j-m93h-cj5j was published for quinn-proto (Rust) Jul 24, 2026
K-Rintaro Credited to K-Rintaro
Deno: Command Injection via spawnSync & spawn on Windows High
CVE-2026-49402 was published for deno (Rust) Jun 16, 2026
kejcao Credited to kejcao
Deno's TLS retry copies stale upgrade hook, risking plaintext traffic High
CVE-2026-44726 was published for deno (Rust) May 27, 2026
r3wretrhy Credited to r3wretrhy
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction High
CVE-2026-47261 was published for wasmtime-wasi (Rust) Jun 5, 2026
shumbo Credited to shumbo
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice) High
CVE-2026-53530 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
mkfifo: permissions of an existing file are changed after FIFO creation fails High
CVE-2026-35341 was published for uu_mkfifo (Rust) Jul 6, 2026
Duplicate Advisory: uutils coreutils allows unauthorized modification of permissions on existing files High
GHSA-w8m4-4v35-v6x3 was published for coreutils (Rust) Apr 22, 2026 withdrawn
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../) High
CVE-2026-35338 was published for uu_chmod (Rust) Jul 6, 2026
Duplicate Advisory: uutils coreutils allows users to bypass the --preserve-root safety mechanism High
GHSA-9gqx-53gp-c8g3 was published for coreutils (Rust) Apr 22, 2026 withdrawn
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow High
CVE-2026-52834 was published for jxl-grid (Rust) Jul 2, 2026
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update High
CVE-2026-52829 was published for zebra-network (Rust) Jul 2, 2026
Haxatron Credited to Haxatron, oxarbitrage, and mpguerra oxarbitrage oxarbitrage
mpguerra mpguerra
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache High
CVE-2026-52736 was published for zebra-state (Rust) Jul 2, 2026
ipwning Credited to ipwning, x15-eth, upbqdn, conradoplg, and mpguerra x15-eth x15-eth
upbqdn upbqdn conradoplg conradoplg mpguerra mpguerra
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call High
GHSA-wjjj-24cx-f28g was published for surrealdb (Rust) Jul 1, 2026
SurrealDB has Denial of Service in JSON parser due to nested objects High
GHSA-q729-696q-g9pq was published for surrealdb (Rust) Jul 1, 2026
DarkaMaul Credited to DarkaMaul
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation High
GHSA-4vgr-h27g-cf9p was published for surrealdb (Rust) Jul 1, 2026
addcontent Credited to addcontent
addcontent Credited to addcontent
scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion High
CVE-2026-46689 was published for kanidm_proto (Rust) May 6, 2026
mbarbero Credited to mbarbero and yaleman yaleman yaleman
miauzxw Credited to miauzxw
ProTip! Advisories are also available from the GraphQL API