Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Smarty Security stream restriction bypass through stream: resource Moderate
CVE-2026-62996 was published for smarty/smarty (Composer) Aug 7, 2026
Faze-up Credited to Faze-up
PHP_CodeSniffer gitblame report command injection via crafted filename High
CVE-2026-67434 was published for squizlabs/php_codesniffer (Composer) Aug 6, 2026
Faze-up Credited to Faze-up, edorian, rodrigoprimo, and jrfnl edorian edorian
rodrigoprimo rodrigoprimo jrfnl jrfnl
Valibot: record() issue paths can make flatten() throw for inherited Object property names Moderate
CVE-2026-59952 was published for valibot (npm) Jul 24, 2026
Faze-up Credited to Faze-up
GitPython unsafe clone option gate bypass through joined short options High
GHSA-v396-v7q4-x2qj was published for GitPython (pip) Jul 21, 2026
Faze-up Credited to Faze-up
protobufjs: Text Format string map parsing can mutate returned map object prototype Moderate
CVE-2026-59876 was published for protobufjs (npm) Jul 20, 2026
Faze-up Credited to Faze-up
Faze-up Credited to Faze-up
ProTip! Advisories are also available from the GraphQL API