Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

79 advisories

Loading
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure High
CVE-2026-55253 was published for langgraph-checkpoint-mongodb (pip) Aug 20, 2026
kenichikawaguchi Credited to kenichikawaguchi
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an... High Unreviewed
CVE-2026-76254 was published Aug 20, 2026
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL Moderate
GHSA-pqh8-p93p-2rx7 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
yotampe-pluto Credited to yotampe-pluto
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution High
GHSA-qw6m-8fw2-2v64 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API