Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,342 advisories

Loading
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` Moderate
CVE-2026-44202 was published for org.openidentityplatform.openam:openam-core (Maven) Jun 22, 2026
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact` Moderate
GHSA-jrpc-7vxp-69p6 was published for org.http4k:http4k-core (Maven) Jun 19, 2026
Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering Moderate
CVE-2026-55847 was published for io.qameta.allure:allure-generator (Maven) Jun 19, 2026
offset Credited to offset and baev baev baev
Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read Moderate
CVE-2026-55846 was published for io.qameta.allure:allure-commandline (Maven) Jun 19, 2026
offset Credited to offset and baev baev baev
Armeria: External Control of File Name or Path in xDS SDS DataSource Moderate
CVE-2026-11752 was published for com.linecorp.armeria:armeria-xds (Maven) Jun 18, 2026
zzoru Credited to zzoru
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463) Moderate
CVE-2026-54683 was published for nl.nl-portal:documenten-api (Maven) Jun 18, 2026
Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator Moderate
CVE-2026-55226 was published for io.strimzi:strimzi (Maven) Jun 18, 2026
katheris Credited to katheris, ppatierno, and scholzj ppatierno ppatierno
scholzj scholzj
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects Moderate
CVE-2026-41280 was published for org.apache.dolphinscheduler:dolphinscheduler-api (Maven) Jun 17, 2026
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature Moderate
CVE-2026-50560 was published for io.netty:netty-codec-http2 (Maven) Jun 15, 2026
ashleytolbert Credited to ashleytolbert
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted Moderate
CVE-2026-50020 was published for io.netty:netty-codec-http (Maven) Jun 15, 2026
chrisvest Credited to chrisvest
Netty: QUIC stateless reset token material exposed through header-visible connection IDs Moderate
CVE-2026-50009 was published for io.netty:netty-codec-classes-quic (Maven) Jun 15, 2026
violetagg Credited to violetagg
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing Moderate
CVE-2026-54697 was published for org.connectbot.sshlib:sshlib (Maven) Jun 12, 2026
Pig-Tail Credited to Pig-Tail and kruton kruton kruton
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation Moderate
CVE-2026-54700 was published for org.connectbot.sshlib:sshlib (Maven) Jun 12, 2026
kruton Credited to kruton
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution Moderate
CVE-2025-58175 was published for org.geoserver.web:gs-web-app (Maven) Jun 12, 2026
lemauanhphong Credited to lemauanhphong and jodygarnett jodygarnett jodygarnett
Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry Moderate
CVE-2026-50634 was published for org.apache.cxf:cxf-rt-rs-security-jose-jaxrs (Maven) Jun 12, 2026
Apache CXF has Authentication Bypass in OAuth2 TokenIntrospectionService Moderate
CVE-2026-50623 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
Apache CXF OAuth2 HTTP Response Splitting via WWW-Authenticate Realm Injection Moderate
CVE-2026-50630 was published for org.apache.cxf:cxf-rt-rs-security-oauth2 (Maven) Jun 12, 2026
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks Moderate
CVE-2026-11986 was published for org.keycloak:keycloak-rest-admin-ui-ext (Maven) Jun 11, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion Moderate
CVE-2026-48043 was published for io.netty:netty-codec-http2 (Maven) Jun 11, 2026
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access Moderate
CVE-2026-48040 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl (Maven) Jun 11, 2026
ProTip! Advisories are also available from the GraphQL API