Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,444 advisories

Loading
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree Moderate
CVE-2026-88000 was published for open-webui (pip) Sep 9, 2026
Classic298 Credited to Classic298
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets Moderate
CVE-2026-88001 was published for open-webui (pip) Sep 9, 2026
arpitjain099 Credited to arpitjain099 and Classic298 Classic298 Classic298
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history Moderate
CVE-2026-88002 was published for open-webui (pip) Sep 9, 2026
YashvantHange Credited to YashvantHange and Classic298 Classic298 Classic298
CyberKareem Credited to CyberKareem
@openhop/server: Path Traversal in Flow ID File Operations High
CVE-2026-59179 was published for @openhop/server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import High
CVE-2026-59176 was published for functype-mcp-server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
Joker linter executed project-local .jokerd/linter.* files during linting High
CVE-2026-59172 was published for github.com/candid82/joker (Go) Sep 9, 2026
Komari: Management Interface CSRF High
GHSA-hxjg-93wc-h8p8 was published for github.com/komari-monitor/komari (Go) Sep 9, 2026
GuangChen2333 Credited to GuangChen2333
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run High
CVE-2026-59160 was published for @yeger/turbo-graph (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients High
CVE-2026-59158 was published for nuxt-ollama (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
webhookd: Unrestricted HTTP Header to Shell Variable Injection Moderate
CVE-2026-59157 was published for github.com/ncarlier/webhookd (Go) Sep 9, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool High
CVE-2026-55864 was published for org.geonetwork-opensource:gn-web-app (Maven) Sep 9, 2026
castilho101 Credited to castilho101, ethiack-admin, juanluisrp, and jodygarnett ethiack-admin ethiack-admin
juanluisrp juanluisrp jodygarnett jodygarnett
smol-toml: Denial of Service via malformed TOML documents High
CVE-2026-85730 was published for smol-toml (npm) Sep 9, 2026
Ravi-lk Credited to Ravi-lk
weasyprint Has Server-Side Request Forgery (SSRF) Moderate
CVE-2026-55073 was published for weasyprint (pip) Sep 9, 2026
ko41a Credited to ko41a
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list` Moderate
CVE-2026-54529 was published for sqladmin (pip) Sep 9, 2026
muslimbek-0x Credited to muslimbek-0x
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service Moderate
CVE-2026-53495 was published for github.com/containerd/containerd (Go) Sep 9, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
7a6163 Credited to 7a6163
decidim-elections: Election question titles allow stored script execution Moderate
CVE-2026-44282 was published for decidim-elections (RubyGems) Sep 9, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint Moderate
CVE-2025-58363 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
kosmosec Credited to kosmosec
LF Edge eKuiper: SSRF in External Service Moderate
CVE-2025-24979 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
LF Edge eKuiper: Self-XSS in External Service Creation Low
CVE-2025-24978 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
gix-sec safe.directory protections absent for elevated administrators Moderate
CVE-2025-24890 was published for gix-sec (Rust) Sep 9, 2026
EliahKagan Credited to EliahKagan
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability Moderate
CVE-2026-69304 was published for Microsoft.AspNetCore.Server.IISIntegration (NuGet) Sep 9, 2026
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability High
CVE-2026-69522 was published for Microsoft.DiaSymReader.Native (NuGet) Sep 9, 2026
ProTip! Advisories are also available from the GraphQL API