Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

113 advisories

Loading
qs: Denial of Service via Attacker Controlled isBuffer Moderate
CVE-2026-82417 was published for qs (npm) Sep 2, 2026
waydeshi Credited to waydeshi and ljharb ljharb ljharb
Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data... Moderate Unreviewed
CVE-2026-72644 was published Sep 1, 2026
muslimbek-0x Credited to muslimbek-0x
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
asteval has a Sandbox Escape via BaseException Subclasses Moderate
CVE-2026-55244 was published for asteval (pip) Aug 20, 2026
mhamzakhattak Credited to mhamzakhattak
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Moderate
CVE-2026-62909 was published for Microsoft.NETCore.App.Runtime.linux-arm (NuGet) Aug 11, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic Moderate
GHSA-3x6r-wxxg-53vv was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
SvelteKit: Big remote form function payloads can cause Node process to crash Moderate
GHSA-wqjv-9729-c5q2 was published for @sveltejs/kit (npm) Jul 24, 2026
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header Moderate
CVE-2026-14631 was published for webpack-dev-server (npm) Jul 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, bjohansebas, Zyy0530, 7thParkk, and UlisesGascon bjohansebas bjohansebas
Zyy0530 Zyy0530 7thParkk 7thParkk UlisesGascon UlisesGascon
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records Moderate
CVE-2026-59875 was published for tar (npm) Jul 20, 2026
Kayiz-PT Credited to Kayiz-PT and bibu123456 bibu123456 bibu123456
ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes Moderate
CVE-2026-53496 was published for exifreader (npm) Jul 17, 2026
YHalo-wyh Credited to YHalo-wyh
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection Moderate
CVE-2026-52739 was published for zebra-state (Rust) Jul 2, 2026
Haxatron Credited to Haxatron, mpguerra, and conradoplg mpguerra mpguerra
conradoplg conradoplg
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks Moderate
CVE-2026-52738 was published for zebra-state (Rust) Jul 2, 2026
sangsoo-osec Credited to sangsoo-osec, mpguerra, and oxarbitrage mpguerra mpguerra
oxarbitrage oxarbitrage
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers Moderate
GHSA-c8w6-x74f-vmg3 was published for zebra-rpc (Rust) Jul 2, 2026
robustfengbin Credited to robustfengbin, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate Moderate
CVE-2026-52731 was published for zebra-rpc (Rust) Jul 2, 2026
sangsoo-osec Credited to sangsoo-osec, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
ts-deepmerge: Prototype Method Override leads to DoS Moderate
CVE-2026-12644 was published for ts-deepmerge (npm) Jun 19, 2026
ProTip! Advisories are also available from the GraphQL API