Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

59 advisories

Loading
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections Moderate
CVE-2026-81890 was published for studio-42/elfinder (Composer) Sep 2, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary High
CVE-2026-63124 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99 and VuiVeIshere VuiVeIshere VuiVeIshere
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages High
CVE-2026-61798 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (Maven) Aug 20, 2026
sondt99 Credited to sondt99
NocoBase backup restore schema name allows command injection Moderate
CVE-2026-55410 was published for @nocobase/plugin-backups (npm) Aug 20, 2026
sondt99 Credited to sondt99
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables Moderate
CVE-2026-63640 was published for magicmirror (npm) Aug 18, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files Moderate
CVE-2026-54706 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
OnionShare Receive mode writes uploaded files even when file uploads are disabled Moderate
CVE-2026-54707 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
CVE-2026-69160 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
CVE-2026-73509 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint High
CVE-2026-73406 was published for @budibase/server (npm) Jul 24, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist High
CVE-2026-59931 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
longcalif Credited to longcalif and sondt99 sondt99 sondt99
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise Critical
CVE-2026-55579 was published for pheditor/pheditor (Composer) Jul 16, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens Moderate
CVE-2026-55513 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting Moderate
CVE-2026-55512 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters High
CVE-2026-52770 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
sondt99 Credited to sondt99
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check Moderate
CVE-2026-53624 was published for github.com/gofiber/fiber (Go) Jul 6, 2026
sondt99 Credited to sondt99, dungNHVhust, gaby, and ReneWerner87 dungNHVhust dungNHVhust
gaby gaby ReneWerner87 ReneWerner87
ProTip! Advisories are also available from the GraphQL API