Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

56 advisories

Loading
SurrealDB has an Uncaught Exception Handling Nonexistent Role Moderate
CVE-2024-58358 was published for surrealdb (Rust) Nov 22, 2024
garyhai Credited to garyhai
Duplicate Advisory: SurrealDB has an Uncaught Exception Handling Nonexistent Role Moderate
GHSA-9qrf-6whp-92w3 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
muslimbek-0x Credited to muslimbek-0x
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
asteval has a Sandbox Escape via BaseException Subclasses Moderate
CVE-2026-55244 was published for asteval (pip) Aug 20, 2026
mhamzakhattak Credited to mhamzakhattak
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic Moderate
GHSA-3x6r-wxxg-53vv was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
SvelteKit: Big remote form function payloads can cause Node process to crash Moderate
GHSA-wqjv-9729-c5q2 was published for @sveltejs/kit (npm) Jul 24, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header Moderate
CVE-2026-14631 was published for webpack-dev-server (npm) Jul 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, bjohansebas, Zyy0530, 7thParkk, and UlisesGascon bjohansebas bjohansebas
Zyy0530 Zyy0530 7thParkk 7thParkk UlisesGascon UlisesGascon
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records Moderate
CVE-2026-59875 was published for tar (npm) Jul 20, 2026
Kayiz-PT Credited to Kayiz-PT and bibu123456 bibu123456 bibu123456
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes Moderate
CVE-2026-53496 was published for exifreader (npm) Jul 17, 2026
YHalo-wyh Credited to YHalo-wyh
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection Moderate
CVE-2026-52739 was published for zebra-state (Rust) Jul 2, 2026
Haxatron Credited to Haxatron, mpguerra, and conradoplg mpguerra mpguerra
conradoplg conradoplg
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks Moderate
CVE-2026-52738 was published for zebra-state (Rust) Jul 2, 2026
sangsoo-osec Credited to sangsoo-osec, mpguerra, and oxarbitrage mpguerra mpguerra
oxarbitrage oxarbitrage
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers Moderate
GHSA-c8w6-x74f-vmg3 was published for zebra-rpc (Rust) Jul 2, 2026
robustfengbin Credited to robustfengbin, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate Moderate
CVE-2026-52731 was published for zebra-rpc (Rust) Jul 2, 2026
sangsoo-osec Credited to sangsoo-osec, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
ts-deepmerge: Prototype Method Override leads to DoS Moderate
CVE-2026-12644 was published for ts-deepmerge (npm) Jun 19, 2026
Deno: Denial of service via non-ASCII bytes in WebSocket response headers Moderate
CVE-2026-55517 was published for deno (Rust) Jun 17, 2026
snoopysecurity Credited to snoopysecurity
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas Moderate
CVE-2026-48038 was published for joi (npm) Jun 11, 2026
kexwin Credited to kexwin
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes Moderate
CVE-2026-45554 was published for nicegui (pip) May 18, 2026
bitinerant Credited to bitinerant, evnchn, and falkoschindler evnchn evnchn
falkoschindler falkoschindler
OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent Moderate
CVE-2026-45676 was published for go.opentelemetry.io/obi (Go) May 18, 2026
MrAlias Credited to MrAlias and rafaelroquetto rafaelroquetto rafaelroquetto
Python-Markdown has an Uncaught Exception Moderate
CVE-2025-69534 was published for Markdown (pip) Mar 5, 2026
ProTip! Advisories are also available from the GraphQL API