Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

38 advisories

Loading
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL Moderate
GHSA-pqh8-p93p-2rx7 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
yotampe-pluto Credited to yotampe-pluto
@asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection Moderate
GHSA-5c7w-4wm3-85vw was published for @asymmetric-effort/specifyjs (npm) Jul 2, 2026
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode Moderate
CVE-2026-54019 was published for open-webui (pip) Jun 17, 2026
0xEr3n Credited to 0xEr3n and Classic298 Classic298 Classic298
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access Moderate
CVE-2026-48121 was published for @langchain/langgraph-checkpoint-mongodb (npm) Jun 12, 2026
Nagendhra-web Credited to Nagendhra-web, etairl, and hntrl etairl etairl
hntrl hntrl
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference Moderate
CVE-2026-41697 was published for org.springframework.data:spring-data-relational (Maven) Jun 10, 2026
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods Moderate
CVE-2026-41696 was published for org.springframework.data:spring-data-mongodb (Maven) Jun 10, 2026
ShellHub has crash-DoS via field injection in filter and sort-by parameters Moderate
CVE-2026-44425 was published for github.com/shellhub-io/shellhub (Go) May 6, 2026
Edu0x01 Credited to Edu0x01
phpMyFAQ has a LIKE Wildcard Injection in Search.php — Unescaped % and _ Metacharacters Enable Broad Content Disclosure Moderate
CVE-2026-34973 was published for thorsten/phpmyfaq (Composer) Apr 1, 2026
athuljayaram Credited to athuljayaram
Sylius has a DQL Injection via API Order Filters Moderate
CVE-2026-31825 was published for sylius/sylius (Composer) Mar 11, 2026
Neosprings Credited to Neosprings and bnBart bnBart bnBart
ProTip! Advisories are also available from the GraphQL API