Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

74 advisories

Loading
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
41Baloo Credited to 41Baloo
manus-use Credited to manus-use
mcollina Credited to mcollina, UlisesGascon, and h0rk1p UlisesGascon UlisesGascon
h0rk1p h0rk1p
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High
GHSA-hrxh-6v49-42gf was published for google.golang.org/grpc (Go) Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header High
CVE-2026-59892 was published for @opentelemetry/propagator-jaeger (npm) Jul 21, 2026
EQSTLab Credited to EQSTLab and pichlermarc pichlermarc pichlermarc
websocket-driver-ruby: Denial of service via malformed Host header High
CVE-2026-61666 was published for websocket-driver (RubyGems) Jul 21, 2026
pranjalithakur Credited to pranjalithakur
Duplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB High
GHSA-f7q6-7rq9-3phx was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Duplicate Advisory: Uncaught Exception in Macro Expecting Native Function to Exist High
GHSA-9qjc-q7hw-vw5r was published for surrealdb (Rust) Jul 18, 2026 withdrawn
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice) High
CVE-2026-53530 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call High
GHSA-wjjj-24cx-f28g was published for surrealdb (Rust) Jul 1, 2026
@grpc/grpc-js: A malformed request can cause a server crash High
CVE-2026-48068 was published for @grpc/grpc-js (npm) Jun 11, 2026
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash High
CVE-2026-48069 was published for @grpc/grpc-js (npm) Jun 11, 2026
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item High
CVE-2026-46545 was published for nimiq-primitives (Rust) May 21, 2026
Piravlos Credited to Piravlos and Eligioo Eligioo Eligioo
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages High
CVE-2026-45685 was published for go.opentelemetry.io/obi (Go) May 18, 2026
MrAlias Credited to MrAlias
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception High
CVE-2026-8161 was published for multiparty (npm) May 18, 2026
Ser0n-ath Credited to Ser0n-ath, bjohansebas, kq5y, ByamB4, blakeembrey, ljharb, and UlisesGascon bjohansebas bjohansebas
kq5y kq5y ByamB4 ByamB4 blakeembrey blakeembrey ljharb ljharb UlisesGascon UlisesGascon
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS) High
CVE-2026-44001 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion High
CVE-2026-46689 was published for kanidm_proto (Rust) May 6, 2026
mbarbero Credited to mbarbero and yaleman yaleman yaleman
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic High
CVE-2026-42544 was published for granian (pip) May 6, 2026
Z-Bra0 Credited to Z-Bra0
kodareef5 Credited to kodareef5
Go JOSE Panics in JWE decryption High
CVE-2026-34986 was published for github.com/go-jose/go-jose (Go) Apr 3, 2026
Haraka affected by DoS via `__proto__` email header High
CVE-2026-34752 was published for Haraka (npm) Apr 1, 2026
sebastianosrt Credited to sebastianosrt and msimerson msimerson msimerson
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error High
CVE-2026-33191 was published for github.com/free5gc/udm (Go) Mar 18, 2026
SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass High
CVE-2026-33203 was published for github.com/siyuan-note/siyuan/kernel (Go) Mar 18, 2026
mith36 Credited to mith36
ProTip! Advisories are also available from the GraphQL API