Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

59 advisories

Loading
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines Moderate
CVE-2026-71311 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
undici vulnerable to CRLF Injection via blob-like body 'type' property Moderate
CVE-2026-15157 was published for undici (npm) Aug 3, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type Moderate
CVE-2026-49756 was published for req (Erlang) Jul 29, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder Moderate
CVE-2026-59921 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
Netty: STOMP CONNECT Frame Header Injection in Netty Moderate
CVE-2026-59920 was published for io.netty:netty-codec-stomp (Maven) Jul 22, 2026
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address Moderate
CVE-2026-59919 was published for io.netty:netty-codec-haproxy (Maven) Jul 22, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs Moderate
CVE-2026-42258 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
guzzlehttp/psr7 has CRLF Injection via URI Host Component Moderate
CVE-2026-49214 was published for guzzlehttp/psr7 (Composer) Jun 11, 2026
edorian Credited to edorian
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address Moderate
CVE-2026-53533 was published for aiosmtplib (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
Net::IMAP: Command Injection via ID command argument Moderate
CVE-2026-47242 was published for net-imap (RubyGems) Jun 9, 2026
nevans Credited to nevans
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument Moderate
CVE-2026-47240 was published for net-imap (RubyGems) Jun 9, 2026
nevans Credited to nevans
Hackney has CRLF / header injection in WebSocket upgrade request Moderate
CVE-2026-47072 was published for hackney (Erlang) Jun 26, 2026
PJUllrich Credited to PJUllrich and maennchen maennchen maennchen
Hackney has CR/LF injection in query parameter Moderate
CVE-2026-47075 was published for hackney (Erlang) Jun 26, 2026
tepel-chen Credited to tepel-chen and maennchen maennchen maennchen
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization Moderate
CVE-2026-55766 was published for guzzlehttp/psr7 (Composer) Jun 19, 2026
iliaal Credited to iliaal
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding Moderate
CVE-2026-9679 was published for undici (npm) Jun 19, 2026
tndud042713 Credited to tndud042713, mcollina, KhafraDev, and UlisesGascon mcollina mcollina
KhafraDev KhafraDev UlisesGascon UlisesGascon
Kirby: Request header injection in `Http\Remote` Moderate
CVE-2026-50188 was published for getkirby/cms (Composer) Jun 18, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands Moderate
CVE-2026-42257 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio and nevans nevans nevans
Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection Moderate
GHSA-268h-hp4c-crq3 was published for nodemailer (npm) Jun 15, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator Moderate
CVE-2026-28970 was published for github.com/apple/swift-nio (Swift) Jun 12, 2026
kuranikaran Credited to kuranikaran and YLChen-007 YLChen-007 YLChen-007
Netty Redis Codec Encoder has a CRLF Injection Issue Moderate
CVE-2026-42586 was published for io.netty:netty-codec-redis (Maven) May 7, 2026
August829 Credited to August829
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields Moderate
CVE-2026-44214 was published for eventsource-encoder (npm) May 8, 2026
Symfony has Email Header Injection via Non-Token Characters in Mime Parameter Names Moderate
CVE-2026-45070 was published for symfony/mime (Composer) May 27, 2026
alexandre-daubois Credited to alexandre-daubois
sse-channel: SSE Injection via unsanitized event fields Moderate
CVE-2026-44217 was published for sse-channel (npm) May 5, 2026
SnailSploit Credited to SnailSploit
Rack's improper unfolding of folded multipart headers preserves CRLF in parsed parameter values Moderate
CVE-2026-26962 was published for rack (RubyGems) Apr 2, 2026
wtn Credited to wtn, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
ProTip! Advisories are also available from the GraphQL API