Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12 advisories

Loading
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets Moderate
CVE-2026-88001 was published for open-webui (pip) Sep 9, 2026
arpitjain099 Credited to arpitjain099 and Classic298 Classic298 Classic298
multer vulnerable to Denial of Service via oversized array index in field names High
CVE-2026-82333 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev, UlisesGascon, and arpitjain099 UlisesGascon UlisesGascon
arpitjain099 arpitjain099
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed High
CVE-2026-83616 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc and arpitjain099 arpitjain099 arpitjain099
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop High
CVE-2026-82397 was published for tornado (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace Moderate
CVE-2026-82398 was published for pypdf (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
arpitjain099 Credited to arpitjain099
sec-reex Credited to sec-reex and arpitjain099 arpitjain099 arpitjain099
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Moderate
CVE-2026-67448 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
arpitjain099 Credited to arpitjain099
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set High
GHSA-fhgh-wq4q-r37x was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
arpitjain099 Credited to arpitjain099
goshs has ACL Bypass & Path Traversal Moderate
CVE-2026-66064 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
goshs has a Path Traversal issue Moderate
CVE-2026-66063 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
python-socketio: Binary attachment accumulation can cause denial of service High
CVE-2026-48804 was published for python-socketio (pip) Jun 26, 2026
mauriceng98 Credited to mauriceng98 and arpitjain099 arpitjain099 arpitjain099
ProTip! Advisories are also available from the GraphQL API