Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

714 advisories

Loading
Spring for GraphQL: Annotation Detection Vulnerability High
CVE-2026-41856 was published for org.springframework.graphql:spring-graphql (Maven) Jun 11, 2026
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata Moderate
CVE-2026-54256 was published for winter/wn-backend-module (Composer) Aug 20, 2026
r00tn0b0dy Credited to r00tn0b0dy and baradika baradika baradika
sondt99 Credited to sondt99
MLflow: trace API endpoints lack proper authorization validators High
CVE-2026-8147 was published for mlflow (pip) Jul 2, 2026
0x00-sys Credited to 0x00-sys
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
Spring Data REST has Improper Access Control in its JSON Patch Implementation High
CVE-2026-41728 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations Moderate
CVE-2026-41837 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Moderate
CVE-2026-54765 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
gooood4u Credited to gooood4u
Electron: Sandboxed iframes can launch external protocol handlers Moderate
CVE-2026-70612 was published for electron (npm) Aug 5, 2026
Electron: Extension tab APIs operate across session boundaries Moderate
CVE-2026-70602 was published for electron (npm) Aug 5, 2026
Foxer131 Credited to Foxer131 and Classic298 Classic298 Classic298
berkdedekarginoglu Credited to berkdedekarginoglu
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL Moderate
CVE-2026-41847 was published for org.springframework:spring-webflux (Maven) Jun 9, 2026
MCP Ruby SDK: Ruby SSE Session Poisoning High
CVE-2026-67431 was published for mcp (RubyGems) Jul 30, 2026
srikanthramu Credited to srikanthramu
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration High
CVE-2026-41006 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite Critical
CVE-2026-64863 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files Critical
CVE-2026-31843 was published for goodoneuz/pay-uz (Composer) Apr 16, 2026
shaxzodbek-uzb Credited to shaxzodbek-uzb
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
ImageMagick: Policy Bypass in script operation due to missing checks Low
GHSA-vghg-5jrg-2398 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
Netty: Security Control Bypass via CORS Short-Circuit Failure Moderate
CVE-2026-56746 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
violetagg Credited to violetagg
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Moderate
CVE-2026-58429 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Pcat2003 Credited to Pcat2003
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
ProTip! Advisories are also available from the GraphQL API