Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,026 advisories

Loading
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation High
CVE-2026-84304 was published for google.golang.org/grpc (Go) Sep 1, 2026
TYPO3 CMS - Broken Access Control in Backend and Install Tool High
CVE-2026-19418 was published for typo3/cms-backend (Composer) Sep 1, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used Moderate
CVE-2026-84306 was published for filament/filament (Composer) Sep 1, 2026
rianorie Credited to rianorie and danharrin danharrin danharrin
Filament: Password validity disclosure for accounts denied panel access on login page Low
CVE-2026-84307 was published for filament/filament (Composer) Sep 1, 2026
danharrin Credited to danharrin
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled High
CVE-2026-77567 was published for filament/filament (Composer) Sep 1, 2026
Orrison Credited to Orrison and danharrin danharrin danharrin
pypdf: Possible long runtimes/large memory usage when retrieving outlines Moderate
CVE-2026-84310 was published for pypdf (pip) Sep 1, 2026
stefan6419846 Credited to stefan6419846 and HYUNSUNG03 HYUNSUNG03 HYUNSUNG03
pypdf: Possible long runtimes/large memory usage when extracting XForm objects Moderate
CVE-2026-84311 was published for pypdf (pip) Sep 1, 2026
zikk090 Credited to zikk090 and stefan6419846 stefan6419846 stefan6419846
pypdf: Possible infinite loop for TreeObject.insert_child Moderate
CVE-2026-84309 was published for pypdf (pip) Sep 1, 2026
alienkeric Credited to alienkeric and stefan6419846 stefan6419846 stefan6419846
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass Moderate
CVE-2026-84371 was published for sanitize-html (npm) Sep 1, 2026
koyokr Credited to koyokr
arpitjain099 Credited to arpitjain099
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
league/commonmark: Denial of service in the SmartPunct and Attributes extensions High
GHSA-jjv6-8j6v-6j52 was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed High
GHSA-f8fg-pg57-v4j8 was published for league/commonmark (Composer) Sep 1, 2026
StarPlatinu Credited to StarPlatinu
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests Moderate
CVE-2026-73229 was published for djangorestframework (pip) Sep 1, 2026
zainnadeem786 Credited to zainnadeem786
nanoid: Integer Overflow or Wraparound High
CVE-2026-73086 was published for nanoid (npm) Sep 1, 2026
alanzabihi Credited to alanzabihi
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes Moderate
CVE-2026-58191 was published for @appium/base-driver (npm) Sep 1, 2026
nikkoenggaliano Credited to nikkoenggaliano
prasanna8585 Credited to prasanna8585
ProTip! Advisories are also available from the GraphQL API