Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

61 advisories

Loading
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF High
CVE-2026-55641 was published for 9router (npm) Aug 28, 2026
EchoSkorJjj Credited to EchoSkorJjj
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() Moderate
CVE-2026-63220 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
DavidCarliez Credited to DavidCarliez
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows... Critical Unreviewed
CVE-2026-58122 was published Jul 10, 2026
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header High
GHSA-rjr7-jggh-pgcp was published for github.com/go-chi/chi/middleware (Go) Jun 25, 2026
rezmoss Credited to rezmoss
Rootingg Credited to Rootingg and cookesan cookesan cookesan
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header Moderate
CVE-2026-48061 was published for litestar (pip) Jun 10, 2026
gik2927 Credited to gik2927
Caddy Defender trusted proxy client IP bypass High
CVE-2026-46415 was published for pkg.jsn.cam/caddy-defender (Go) May 19, 2026
JasonLovesDoggo Credited to JasonLovesDoggo
Shynet before 0.14.0 allows Host header injection in the password reset flow. Moderate Unreviewed
CVE-2026-35507 was published Apr 3, 2026
smaeljaish771 Credited to smaeljaish771 and KeenSecurityLab KeenSecurityLab KeenSecurityLab
AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr() Moderate
CVE-2026-33690 was published for wwbn/avideo (Composer) Mar 25, 2026
ZeroXJacks Credited to ZeroXJacks
TinkAnet Credited to TinkAnet, climba03003, mcollina, and UlisesGascon climba03003 climba03003
mcollina mcollina UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API