Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,905 advisories

Loading
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict High
CVE-2026-56669 was published for elysia (npm) Sep 23, 2026
jviide Credited to jviide
ReactPress has SQL injection via dynamic column names in TypeORM query builders High
CVE-2026-61685 was published for @fecommunity/reactpress (npm) Sep 23, 2026
lsr365400 Credited to lsr365400
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length Moderate
GHSA-8pcw-h6w9-h46g was published for plone.app.contenttypes (pip) Sep 23, 2026
viliald Credited to viliald
plone.app.dexterity has a Denial of Service due to excessive title or description length Moderate
CVE-2026-57576 was published for plone.app.dexterity (pip) Sep 23, 2026
viliald Credited to viliald
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget High
CVE-2026-77394 was published for @openc3/vue-common (npm) Sep 23, 2026
ArpitKubadia Credited to ArpitKubadia
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS High
CVE-2026-82407 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery High
CVE-2026-82409 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace High
CVE-2026-82406 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Jawn: Quadratic parsing effort in AsyncParser High
CVE-2026-61814 was published for org.typelevel:jawn-parser_2.12 (Maven) Sep 23, 2026
rossabaker Credited to rossabaker and samspills samspills samspills
Jawn: Uncontrolled nesting depth in JSON parser High
CVE-2026-59990 was published for org.typelevel:jawn-parser_2.12 (Maven) Sep 23, 2026
rossabaker Credited to rossabaker and eed3si9n eed3si9n eed3si9n
mabdullah22 Credited to mabdullah22
ch4r0utf8 Credited to ch4r0utf8
Klever-Go: /log controls global node logging High
CVE-2026-86064 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint Moderate
CVE-2026-93421 was published for mesop (pip) Sep 23, 2026
5H4D0WBY73 Credited to 5H4D0WBY73
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting High
CVE-2026-77601 was published for openc3 (RubyGems) Sep 23, 2026
Marnick39 Credited to Marnick39
Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service High
CVE-2026-61695 was published for github.com/square/wire (Swift) Sep 23, 2026
tonghuaroot Credited to tonghuaroot
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) Moderate
CVE-2026-92692 was published for sulu/sulu (Composer) Sep 23, 2026
JLine: ReDoS in Nano Editor Regex Search Mode Moderate
CVE-2026-77421 was published for org.jline:jline-builtins (Maven) Sep 23, 2026
sectroyer Credited to sectroyer
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping High
CVE-2026-77422 was published for org.jline:jline-builtins (Maven) Sep 23, 2026
sectroyer Credited to sectroyer
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade High
CVE-2026-56679 was published for 9router (npm) Sep 23, 2026
ngxuankhoi Credited to ngxuankhoi
9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding Moderate
CVE-2026-56678 was published for 9router (npm) Sep 23, 2026
dinhvaren Credited to dinhvaren
ProTip! Advisories are also available from the GraphQL API