Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

210 advisories

Loading
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys High
CVE-2026-54511 was published for @logtape/syslog (npm) Aug 26, 2026
An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an... Critical Unreviewed
CVE-2026-72590 was published Aug 10, 2026
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines Moderate
CVE-2026-71311 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
undici vulnerable to CRLF Injection via blob-like body 'type' property Moderate
CVE-2026-15157 was published for undici (npm) Aug 3, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type Moderate
CVE-2026-49756 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows... Moderate Unreviewed
CVE-2026-57511 was published Jul 28, 2026
ProTip! Advisories are also available from the GraphQL API