Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

73 advisories

Loading
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Socket.IO: Engine.IO Protocol Revision Mismatch DoS High
CVE-2026-102599 was published for engine.io (npm) Sep 29, 2026
sondt99 Credited to sondt99
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses Moderate
CVE-2026-85709 was published for lightrag-hku (pip) Sep 22, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service Moderate
CVE-2026-77561 was published for github.com/steveiliop56/tinyauth (Go) Sep 22, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files High
CVE-2026-77253 was published for mcp-atlassian (pip) Sep 22, 2026
sondt99 Credited to sondt99
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service High
CVE-2026-81876 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service High
CVE-2026-81875 was published for ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven) Sep 17, 2026
sondt99 Credited to sondt99
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured High
CVE-2026-78682 was published for nltk (pip) Sep 8, 2026
sondt99 Credited to sondt99
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions Moderate
CVE-2026-63733 was published for surrealdb-core (Rust) Sep 4, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root Moderate
CVE-2026-61625 was published for github.com/VictoriaMetrics/VictoriaMetrics (Go) Sep 3, 2026
sondt99 Credited to sondt99, dungNHVhust, arkid15r, and makasim dungNHVhust dungNHVhust
arkid15r arkid15r makasim makasim
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections Moderate
CVE-2026-81890 was published for studio-42/elfinder (Composer) Sep 2, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary High
CVE-2026-63124 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99 and VuiVeIshere VuiVeIshere VuiVeIshere
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages High
CVE-2026-61798 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (Maven) Aug 20, 2026
sondt99 Credited to sondt99
NocoBase backup restore schema name allows command injection Moderate
CVE-2026-55410 was published for @nocobase/plugin-backups (npm) Aug 20, 2026
sondt99 Credited to sondt99
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables Moderate
CVE-2026-63640 was published for magicmirror (npm) Aug 18, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files Moderate
CVE-2026-54706 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
OnionShare Receive mode writes uploaded files even when file uploads are disabled Moderate
CVE-2026-54707 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
ProTip! Advisories are also available from the GraphQL API