Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,554 advisories

Loading
unstructured: Server-Side Request Forgery in the URL-based partitioning Critical
CVE-2026-71428 was published for unstructured (pip) Sep 3, 2026
hayato1121 Credited to hayato1121
Snipe-IT has an Open Redirect After User Edit Moderate
CVE-2026-55461 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none Moderate
CVE-2026-55834 was published for github.com/pocket-id/pocket-id/backend (Go) Aug 28, 2026
geo-chen Credited to geo-chen
WebOb: Open redirect in Location header normalization via leading C0 control / space characters Moderate
CVE-2026-54770 was published for webob (pip) Aug 27, 2026
tonghuaroot Credited to tonghuaroot, digitalresistor, and polkorny digitalresistor digitalresistor
polkorny polkorny
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter Low
CVE-2026-42350 was published for github.com/akuity/kargo (Go) Aug 27, 2026
PontusHanssen Credited to PontusHanssen, krancour, and rpelczar krancour krancour
rpelczar rpelczar
Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in... High Unreviewed
CVE-2026-79662 was published Aug 25, 2026
ProTip! Advisories are also available from the GraphQL API