Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

136 advisories

Loading
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability High
CVE-2026-50524 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read Moderate
CVE-2026-52763 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
CosmicCrusader23 Credited to CosmicCrusader23
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions High
CVE-2026-2092 was published for org.keycloak:keycloak-services (Maven) Jul 2, 2026
1seal Credited to 1seal
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels Moderate
CVE-2026-54235 was published for vllm (pip) Jun 17, 2026
brodmart Credited to brodmart and jperezdealgaba jperezdealgaba jperezdealgaba
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection Moderate
CVE-2026-47675 was published for hono (npm) Jun 4, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims Moderate
CVE-2026-45069 was published for symfony/security-http (Composer) May 27, 2026
Mattermost doesn't validate user-supplied input in API request handlers Moderate
CVE-2026-4646 was published for github.com/mattermost/mattermost-plugin-github (Go) May 26, 2026
Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status Low
CVE-2026-7887 was published for concrete5/concrete5 (Composer) May 22, 2026
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header High
CVE-2026-33806 was published for fastify (npm) Apr 15, 2026
mcollina Credited to mcollina, climba03003, jsumners, and UlisesGascon climba03003 climba03003
jsumners jsumners UlisesGascon UlisesGascon
TSPortal: Any user can forge self-deletion requests for any account High
CVE-2026-29788 was published for miraheze/ts-portal (Composer) Mar 27, 2026
pskyechology Credited to pskyechology and Universal-Omega Universal-Omega Universal-Omega
jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs High
CVE-2026-4598 was published for jsrsasign (npm) Mar 23, 2026
Duplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions High
GHSA-wmxr-6j5f-838p was published for org.keycloak:keycloak-saml-adapter-core (Maven) Mar 18, 2026 withdrawn
1seal Credited to 1seal
ProTip! Advisories are also available from the GraphQL API