Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,283 advisories

Loading
Shirshakhtml Credited to Shirshakhtml
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload High
CVE-2026-79921 was published for github.com/rabbitmq/amqp091-go (Go) Sep 3, 2026
suchitd Credited to suchitd
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close Moderate
CVE-2026-63670 was published for sanitize-html (npm) Sep 3, 2026
bibu123456 Credited to bibu123456
Material for MkDocs: DOM XSS in search suggestions via query parameter Moderate
CVE-2026-73295 was published for mkdocs-material (pip) Sep 3, 2026
p- Credited to p-
TOON: Prototype pollution when decoding untrusted TOON input High
CVE-2026-82404 was published for @toon-format/toon (npm) Sep 3, 2026
ckorhonen Credited to ckorhonen
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) High
CVE-2026-73222 was published for claude-code-templates (npm) Sep 3, 2026
spartan8806 Credited to spartan8806
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision High
CVE-2026-73293 was published for github.com/semaphoreui/semaphore (Go) Sep 3, 2026
kah-ja Credited to kah-ja
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation High
CVE-2026-73292 was published for github.com/semaphoreui/semaphore (Go) Sep 3, 2026
CamilleGR Credited to CamilleGR
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) Critical
CVE-2026-62681 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via header-parameter default -> zod module-level template literal Critical
CVE-2026-71871 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator Critical
CVE-2026-71867 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via enum-typed default -> zod module-level template literal Critical
CVE-2026-71868 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli Critical
CVE-2026-71865 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, aqeelat, and mohammad228 mrostamipoor mrostamipoor
aqeelat aqeelat mohammad228 mohammad228
ffuf denial of service (OOM) via HTTP response decompression bomb High
CVE-2026-73232 was published for github.com/ffuf/ffuf (Go) Sep 3, 2026
Tricta Credited to Tricta
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root Moderate
CVE-2026-61625 was published for github.com/VictoriaMetrics/VictoriaMetrics (Go) Sep 3, 2026
sondt99 Credited to sondt99, dungNHVhust, arkid15r, and makasim dungNHVhust dungNHVhust
arkid15r arkid15r makasim makasim
LiquidJS has an infinite loop vulnerability in its `strip_html` filter High
CVE-2026-61556 was published for liquidjs (npm) Sep 3, 2026
NariyoshiChida Credited to NariyoshiChida
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool Moderate
CVE-2026-75602 was published for github.com/OpenListTeam/OpenList (Go) Sep 3, 2026
ILoveScratch2 Credited to ILoveScratch2, j2rong4cn, Suyunmeng, and jyxjjj j2rong4cn j2rong4cn
Suyunmeng Suyunmeng jyxjjj jyxjjj
OpenClaw Feishu permission tools could ignore per-account disablement High
GHSA-w8wf-3qvj-6xqf was published for @openclaw/feishu (npm) Sep 3, 2026
rexpository Credited to rexpository
OpenClaw Feishu tools could ignore per-account disablement High
GHSA-2q7j-2vhx-56g8 was published for @openclaw/feishu (npm) Sep 3, 2026
rexpository Credited to rexpository
ProTip! Advisories are also available from the GraphQL API