Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

110 advisories

Loading
41Baloo Credited to 41Baloo
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
CVE-2026-73430 was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
CVE-2026-73429 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Socket.IO: Zero-attachment Memory Exhaustion High
CVE-2026-69185 was published for socket.io-parser (npm) Aug 3, 2026
aretekzs Credited to aretekzs, mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk mauriceng98 mauriceng98
Zyy0530 Zyy0530 Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
protobufjs : Schema-derived names can shadow runtime-significant properties Moderate
CVE-2026-54269 was published for protobufjs (npm) Jun 15, 2026
acorn421 Credited to acorn421 and dcodeIO dcodeIO dcodeIO
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) Moderate
CVE-2026-35366 was published for uu_printenv (Rust) Jul 6, 2026
Duplicate Advisory: uutils coreutils has an Improper Check for Unusual or Exceptional Conditions Moderate
GHSA-7259-cwhx-3xx3 was published for coreutils (Rust) Apr 22, 2026 withdrawn
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS) Moderate
CVE-2026-35369 was published for uu_kill (Rust) Jul 6, 2026
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers Moderate
GHSA-c8w6-x74f-vmg3 was published for zebra-rpc (Rust) Jul 2, 2026
robustfengbin Credited to robustfengbin, mpguerra, and upbqdn mpguerra mpguerra
upbqdn upbqdn
LucyEgan Credited to LucyEgan
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call High
GHSA-wjjj-24cx-f28g was published for surrealdb (Rust) Jul 1, 2026
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing Moderate
CVE-2026-4915 was published for github.com/mattermost/mattermost-server (Go) May 26, 2026
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads High
CVE-2026-45678 was published for go.opentelemetry.io/obi (Go) May 18, 2026
MrAlias Credited to MrAlias, grcevski, and rafaelroquetto grcevski grcevski
rafaelroquetto rafaelroquetto
Clerk has an authorization bypass when combining organization, billing, or reverification checks High
CVE-2026-42349 was published for @clerk/astro (npm) Apr 30, 2026
LinZiyuu Credited to LinZiyuu
LinZiyuu Credited to LinZiyuu
LinZiyuu Credited to LinZiyuu
LinZiyuu Credited to LinZiyuu
Mattermost doesn't validate the response body of proxied images Moderate
CVE-2026-4054 was published for github.com/mattermost/mattermost-server (Go) May 15, 2026
net-imap vulnerable to STARTTLS stripping via invalid response timing High
CVE-2026-42246 was published for net-imap (RubyGems) May 4, 2026
Masamuneee Credited to Masamuneee
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts High
CVE-2026-40069 was published for bsv-sdk (RubyGems) Apr 9, 2026
sgbett Credited to sgbett
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2024-4367 was published for pdfjs-dist (npm) May 7, 2024
ThomasRinsma Credited to ThomasRinsma
Admidio Missing Minimum Administrator Check in Role Membership Removal Moderate
CVE-2026-41662 was published for admidio/admidio (Composer) Apr 29, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig High
CVE-2026-25639 was published for axios (npm) Feb 9, 2026
hackerman70000 Credited to hackerman70000 and FeBe95 FeBe95 FeBe95
ProTip! Advisories are also available from the GraphQL API