Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,473 advisories

Loading
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms High
CVE-2026-54291 was published for org.postgresql:postgresql (Maven) Jul 21, 2026
KEIJOT Credited to KEIJOT
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability High
CVE-2026-56170 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Jul 21, 2026
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability High
CVE-2026-50526 was published for Microsoft.NET.Build.Containers (NuGet) Jul 21, 2026
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability High
CVE-2026-47300 was published for Microsoft.AspNetCore.Authentication.Negotiate (NuGet) Jul 21, 2026
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability High
CVE-2026-47303 was published for Microsoft.AspNetCore.Authentication.Negotiate (NuGet) Jul 21, 2026
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability High
CVE-2026-50527 was published for System.Security.Cryptography.Xml (NuGet) Jul 21, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability High
CVE-2026-50650 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references Low
GHSA-8whx-365g-h9vv was published for loofah (RubyGems) Jul 21, 2026
connorshea Credited to connorshea
Guzzle: URI fragments disclosed in redirect Referer headers Moderate
GHSA-h95v-h523-3mw8 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Host-only cookie scope is not preserved Moderate
GHSA-wm3w-8rrp-j577 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-f283-ghqc-fg79 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
jlgore Credited to jlgore
sec-reex Credited to sec-reex
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
alanturing881 Credited to alanturing881
thientd Credited to thientd
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields Moderate
CVE-2026-59728 was published for @astrojs/rss (npm) Jul 20, 2026
alanturing881 Credited to alanturing881
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Serotav Credited to Serotav
Brubbish Credited to Brubbish
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service Moderate
CVE-2026-59203 was published for pillow (pip) Jul 20, 2026
jiagongzheng-stack Credited to jiagongzheng-stack
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() High
CVE-2026-59200 was published for Pillow (pip) Jul 20, 2026
redyank Credited to redyank
Serotav Credited to Serotav
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images Moderate
CVE-2026-59198 was published for Pillow (pip) Jul 20, 2026
Serotav Credited to Serotav
Serotav Credited to Serotav
ProTip! Advisories are also available from the GraphQL API