Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

136 advisories

Loading
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
41Baloo Credited to 41Baloo
muslimbek-0x Credited to muslimbek-0x
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
asteval has a Sandbox Escape via BaseException Subclasses Moderate
CVE-2026-55244 was published for asteval (pip) Aug 20, 2026
mhamzakhattak Credited to mhamzakhattak
manus-use Credited to manus-use
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic Moderate
GHSA-3x6r-wxxg-53vv was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
mcollina Credited to mcollina, UlisesGascon, and h0rk1p UlisesGascon UlisesGascon
h0rk1p h0rk1p
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
SvelteKit: Big remote form function payloads can cause Node process to crash Moderate
GHSA-wqjv-9729-c5q2 was published for @sveltejs/kit (npm) Jul 24, 2026
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High
GHSA-hrxh-6v49-42gf was published for google.golang.org/grpc (Go) Jul 21, 2026
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header High
CVE-2026-59892 was published for @opentelemetry/propagator-jaeger (npm) Jul 21, 2026
EQSTLab Credited to EQSTLab and pichlermarc pichlermarc pichlermarc
websocket-driver-ruby: Denial of service via malformed Host header High
CVE-2026-61666 was published for websocket-driver (RubyGems) Jul 21, 2026
pranjalithakur Credited to pranjalithakur
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header Moderate
CVE-2026-14631 was published for webpack-dev-server (npm) Jul 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, bjohansebas, Zyy0530, 7thParkk, and UlisesGascon bjohansebas bjohansebas
Zyy0530 Zyy0530 7thParkk 7thParkk UlisesGascon UlisesGascon
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records Moderate
CVE-2026-59875 was published for tar (npm) Jul 20, 2026
Kayiz-PT Credited to Kayiz-PT and bibu123456 bibu123456 bibu123456
Duplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB High
GHSA-f7q6-7rq9-3phx was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Duplicate Advisory: Uncaught Exception in Macro Expecting Native Function to Exist High
GHSA-9qjc-q7hw-vw5r was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Duplicate Advisory: SurrealDB has an Uncaught Exception Handling Nonexistent Role Moderate
GHSA-9qrf-6whp-92w3 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes Moderate
CVE-2026-53496 was published for exifreader (npm) Jul 17, 2026
YHalo-wyh Credited to YHalo-wyh
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys Low
CVE-2026-54541 was published for nimiq-primitives (Rust) Jul 16, 2026
paberr Credited to paberr and Piravlos Piravlos Piravlos
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice) High
CVE-2026-53530 was published for ratex-parser (Rust) Jul 7, 2026
nikkoenggaliano Credited to nikkoenggaliano
ProTip! Advisories are also available from the GraphQL API