Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,342 advisories

Loading
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass Moderate
CVE-2026-59900 was published for io.netty:netty-codec-http2 (Maven) Jul 22, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service Moderate
CVE-2026-59899 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation Moderate
CVE-2026-59898 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: Security Control Bypass via CORS Short-Circuit Failure Moderate
CVE-2026-56746 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
violetagg Credited to violetagg
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem and mprins mprins mprins
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)` Moderate
GHSA-mhm7-754m-9p8w was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy Moderate
CVE-2026-59888 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
omkhar Credited to omkhar
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center Moderate
CVE-2025-32781 was published for com.ctrip.framework.apollo:apollo (Maven) Jul 13, 2026
lesignals Credited to lesignals
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization Moderate
CVE-2026-49844 was published for org.apache.logging.log4j:log4j-api (Maven) Jul 11, 2026
ppkarwasz Credited to ppkarwasz, ashwani945, and Lueton ashwani945 ashwani945
Lueton Lueton
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers Moderate
GHSA-q6gh-6v2r-hjv3 was published for io.micronaut:micronaut-http-client (Maven) Jul 9, 2026
sdelamo Credited to sdelamo
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries Moderate
CVE-2026-49463 was published for nl.nl-portal:besluiten (Maven) Jul 8, 2026
DSpace: Path Traversal is possible through LDN message generation Moderate
CVE-2026-49833 was published for org.dspace:dspace-api (Maven) Jul 8, 2026
superpegaso2703 Credited to superpegaso2703 and kshepherd kshepherd kshepherd
DSpace: ORE resource URI does not validate scheme for non-web resources Moderate
CVE-2026-49830 was published for org.dspace:dspace-api (Maven) Jul 8, 2026
superpegaso2703 Credited to superpegaso2703 and kshepherd kshepherd kshepherd
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path Moderate
CVE-2026-49831 was published for org.dspace:dspace-api (Maven) Jul 8, 2026
superpegaso2703 Credited to superpegaso2703 and kshepherd kshepherd kshepherd
OpenRemote read-only asset users can write predicted datapoints Moderate
CVE-2026-49439 was published for io.openremote:openremote-manager (Maven) Jul 6, 2026
Hussien-Alzaghateet Credited to Hussien-Alzaghateet
OpenAM OAuth Authorization Bypass via PKCE Challenge Moderate
CVE-2026-48717 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jun 29, 2026
wodzen Credited to wodzen
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution Moderate
CVE-2026-53914 was published for org.jetbrains.kotlin:kotlin-gradle-plugin (Maven) Jun 26, 2026
marcelstoer Credited to marcelstoer and Lueton Lueton Lueton
nextflow auth login command has incorrect default permissions Moderate
CVE-2026-48722 was published for io.nextflow:nextflow (Maven) Jun 25, 2026
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation Moderate
CVE-2026-48480 was published for io.netty.incubator:netty-incubator-codec-ohttp (Maven) Jun 23, 2026
jackson-databind has @JsonView bypass for setterless creator properties Moderate
CVE-2026-54517 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields Moderate
CVE-2026-54516 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties Moderate
CVE-2026-54515 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar, pjfanning, snieguu, ataillefer, and surli pjfanning pjfanning
snieguu snieguu ataillefer ataillefer surli surli
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF) Moderate
CVE-2026-54514 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString() Moderate
CVE-2026-50193 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
deniz-husaj Credited to deniz-husaj and cowtowncoder cowtowncoder cowtowncoder
jackson-databind has a @JsonView bypass for unwrapped creator parameters Moderate
CVE-2026-54518 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jun 23, 2026
omkhar Credited to omkhar
ProTip! Advisories are also available from the GraphQL API