Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,893 advisories

Loading
Spinnaker has non-safe yaml deserialization, allowing RCE when using specific types High
CVE-2026-44795 was published for io.spinnaker.orca:orca-core (Maven) Jun 22, 2026
connorshea Credited to connorshea
Keycloak has an Authentication Bypass by Primary Weakness Moderate
CVE-2026-9798 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
Keycloak has an Improper Verification of Cryptographic Signature issue Moderate
CVE-2026-9793 was published for org.keycloak:keycloak-services (Maven) May 28, 2026
Keycloak Services has Improper Validation of Consistency within Input Moderate
CVE-2026-9689 was published for org.keycloak:keycloak-services (Maven) May 27, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion Moderate
CVE-2026-48043 was published for io.netty:netty-codec-http2 (Maven) Jun 11, 2026
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion High
CVE-2026-48059 was published for io.netty:netty-codec-haproxy (Maven) Jun 11, 2026
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator High
CVE-2026-48006 was published for io.netty:netty-codec-redis (Maven) Jun 11, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title High
CVE-2025-66024 was published for org.xwiki.contrib.blog:application-blog-ui (Maven) Mar 4, 2026
lukasz-rybak Credited to lukasz-rybak and sealbenb sealbenb sealbenb
CometVisu Backend for openHAB affected by SSRF/XSS High
CVE-2024-42467 was published for org.openhab.ui.bundles:org.openhab.ui.cometvisu (Maven) Aug 9, 2024
p- Credited to p-, peuter, and sealbenb peuter peuter
sealbenb sealbenb
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service High
CVE-2026-45799 was published for com.squareup.wire:wire-runtime (Maven) May 19, 2026
TrekLaps Credited to TrekLaps and tal-sealsecurity tal-sealsecurity tal-sealsecurity
json-smart Uncontrolled Recursion vulnerability High
CVE-2023-1370 was published for net.minidev:json-smart (Maven) Mar 23, 2023
oswaldobapvicjr Credited to oswaldobapvicjr
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion High
CVE-2026-48748 was published for io.netty:netty-codec-http3 (Maven) Jun 15, 2026
violetagg Credited to violetagg and julianladisch julianladisch julianladisch
Netty has Insufficient Bailiwick Validation for NS Records High
CVE-2026-47691 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records High
CVE-2026-45674 was published for io.netty:netty-resolver-dns (Maven) Jun 8, 2026
violetagg Credited to violetagg
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem and mprins mprins mprins
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback Critical
CVE-2026-62379 was published for org.openidentityplatform.openam:openam-core (Maven) Jul 24, 2026
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases Critical
CVE-2026-44221 was published for com.arcadedb:arcadedb-server (Maven) May 5, 2026
sealbenb Credited to sealbenb
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-72hv-8253-57qq was published for com.fasterxml.jackson.core:jackson-core (Maven) Feb 28, 2026
sprabhav7 Credited to sprabhav7, rohan-repos, neilmadden-hazelcast, awsactran, and cowtowncoder rohan-repos rohan-repos
neilmadden-hazelcast neilmadden-hazelcast awsactran awsactran cowtowncoder cowtowncoder
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
core-geonetwork has an Open Redirect Bypass Moderate
CVE-2026-53573 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 31, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and juanluisrp RacerZ-fighting RacerZ-fighting
juanluisrp juanluisrp
jinjava has Sandbox Bypass via JavaType-Based Deserialization Critical
CVE-2025-59340 was published for com.hubspot.jinjava:jinjava (Maven) Sep 17, 2025
taisehub Credited to taisehub, odgrso, jasmith-hs, and sealbenb odgrso odgrso
jasmith-hs jasmith-hs sealbenb sealbenb
Spring Data: Unbounded property-path cache keyed by externally-supplied path string High
CVE-2026-41695 was published for org.springframework.data:spring-data-commons (Maven) Jul 31, 2026
Spring Framework Cross-site Scripting via JSP Form Tags Moderate
CVE-2026-41846 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux Moderate
CVE-2026-41853 was published for org.springframework:spring-webflux (Maven) Jun 9, 2026
ProTip! Advisories are also available from the GraphQL API