Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,283 advisories

Loading
Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits Moderate
CVE-2026-61690 was published for getgrav/grav (Composer) Sep 2, 2026
alienkeric Credited to alienkeric
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 High
CVE-2026-61704 was published for link-preview-js (npm) Sep 2, 2026
ahmet-sahiner Credited to ahmet-sahiner
baeseungwon1010 Credited to baeseungwon1010, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization High
CVE-2026-75975 was published for fast-uri (npm) Sep 2, 2026
mcollina Credited to mcollina and UlisesGascon UlisesGascon UlisesGascon
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding High
CVE-2026-75899 was published for fast-uri (npm) Sep 2, 2026
NotAFlightRisk Credited to NotAFlightRisk, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-uri vulnerable to host confusion via percent-encoded scheme normalization High
CVE-2026-76172 was published for fast-uri (npm) Sep 2, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
NLTK: Default ENFORCE=False Disables All pathsec Security Controls High
CVE-2026-62388 was published for nltk (pip) Sep 2, 2026
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure Moderate
CVE-2026-63311 was published for nltk (pip) Sep 2, 2026
ekaf Credited to ekaf
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization Moderate
CVE-2026-83610 was published for @xmldom/xmldom (npm) Sep 2, 2026
Paranoidgrinch Credited to Paranoidgrinch
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown High
CVE-2026-76098 was published for mistune (pip) Sep 2, 2026
wan1yan Credited to wan1yan
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count Moderate
CVE-2026-16732 was published for fastify (npm) Sep 2, 2026
alimony Credited to alimony, mcollina, climba03003, and UlisesGascon mcollina mcollina
climba03003 climba03003 UlisesGascon UlisesGascon
fastify vulnerable to schema validation bypass via root primitive coercion mismatch Moderate
CVE-2026-18504 was published for fastify (npm) Sep 2, 2026
velgusgus599 Credited to velgusgus599, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS High
CVE-2026-71553 was published for apostrophe (npm) Sep 2, 2026
Sulu: Stored XSS via media download inline-disposition override Moderate
CVE-2026-82396 was published for sulu/sulu (Composer) Sep 2, 2026
0x3xP01t3r Credited to 0x3xP01t3r
Sulu: Fix authorization bypass when creating preview links Moderate
CVE-2026-82394 was published for sulu/sulu (Composer) Sep 2, 2026
Sulu: Media move/update authorization bypass (IDOR) Moderate
CVE-2026-82395 was published for sulu/sulu (Composer) Sep 2, 2026
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
Kirby: Access to image files outside of the site root via path traversal in the media handling Moderate
CVE-2026-75592 was published for getkirby/cms (Composer) Sep 2, 2026
0x1saac Credited to 0x1saac
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query-parameter default -> zod module-level template literal Critical
CVE-2026-72716 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`) Moderate
CVE-2026-73845 was published for @aborruso/ckan-mcp-server (npm) Sep 2, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control Critical
CVE-2026-72920 was published for github.com/seaweedfs/seaweedfs (Go) Sep 2, 2026
KadirArslan Credited to KadirArslan
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() High
CVE-2026-64850 was published for getgrav/grav (Composer) Sep 2, 2026
YuvalMil Credited to YuvalMil, MatiHub25, and LeonKaya MatiHub25 MatiHub25
LeonKaya LeonKaya
qs array-limit bypass via bracket-key comma parsing Moderate
CVE-2026-82562 was published for qs (npm) Sep 2, 2026
Vectrain51 Credited to Vectrain51, Fcmam5, and ljharb Fcmam5 Fcmam5
ljharb ljharb
ProTip! Advisories are also available from the GraphQL API