Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,328 advisories

Loading
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI Moderate
CVE-2026-54147 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite Moderate
CVE-2026-59903 was published for io.netty:netty-codec-http (Maven) Aug 17, 2026
violetagg Credited to violetagg
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
jsoup: Cleaner may expose markup with custom raw-text elements Moderate
CVE-2026-71497 was published for org.jsoup:jsoup (Maven) Aug 6, 2026
quitbug Credited to quitbug and jhy jhy jhy
core-geonetwork has an Open Redirect Bypass Moderate
CVE-2026-53573 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 31, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and juanluisrp RacerZ-fighting RacerZ-fighting
juanluisrp juanluisrp
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Moderate
CVE-2026-64607 was published for org.apache.httpcomponents.client5:httpclient5 (Maven) Jul 31, 2026
Lueton Credited to Lueton
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Moderate
CVE-2026-54704 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
FWinkler79 Credited to FWinkler79
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion Moderate
CVE-2026-54712 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
decsecre583 Credited to decsecre583
veraPDF Parser DoS via PostScript Type 1 Font Programs Moderate
CVE-2026-54081 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF Parser DoS via PostScript CMap Streams Moderate
CVE-2026-54080 was published for org.verapdf:parser (Maven) Jul 29, 2026
wodzen Credited to wodzen
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs Moderate
CVE-2026-54082 was published for org.verapdf:validation-model (Maven) Jul 29, 2026
acornall Credited to acornall
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages Moderate
CVE-2023-37465 was published for org.xwiki.contrib:discussions-server (Maven) Jul 27, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names Moderate
CVE-2026-73508 was published for io.netty:netty-codec-dns (Maven) Jul 24, 2026
violetagg Credited to violetagg
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges Moderate
CVE-2026-59949 was published for at.yawk.lz4:lz4-java (Maven) Jul 24, 2026
sectroyer Credited to sectroyer
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets Moderate
CVE-2026-55223 was published for com.mchange:c3p0 (Maven) Jul 23, 2026
Eclipse Jetty: Path parameter traversal Moderate
CVE-2026-8384 was published for org.eclipse.jetty:jetty-util (Maven) Jul 22, 2026
jweny Credited to jweny
Eclipse Jetty: HTTP Authority/Host mismatch Moderate
CVE-2026-6790 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections Moderate
CVE-2026-10051 was published for org.eclipse.jetty:jetty-server (Maven) Jul 22, 2026
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder Moderate
CVE-2026-59921 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty Moderate
CVE-2026-59920 was published for io.netty:netty-codec-stomp (Maven) Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address Moderate
CVE-2026-59919 was published for io.netty:netty-codec-haproxy (Maven) Jul 22, 2026
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass Moderate
CVE-2026-59900 was published for io.netty:netty-codec-http2 (Maven) Jul 22, 2026
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service Moderate
CVE-2026-59899 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation Moderate
CVE-2026-59898 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
ProTip! Advisories are also available from the GraphQL API