Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,569 advisories

Loading
fast-uri vulnerable to host confusion via literal backslash authority delimiter High
CVE-2026-16221 was published for fast-uri (npm) Jul 21, 2026
rampage0010 Credited to rampage0010, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits High
GHSA-8r6m-32jq-jx6q was published for fast-xml-parser (npm) Jul 21, 2026
the-vibe-dev Credited to the-vibe-dev and amitguptagwl amitguptagwl amitguptagwl
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL High
GHSA-rwj8-pgh3-r573 was published for gitpython (pip) Jul 21, 2026
KrisKennawayDD Credited to KrisKennawayDD
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
GHSA-9mqv-5hh9-4cgg was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High
GHSA-hrxh-6v49-42gf was published for google.golang.org/grpc (Go) Jul 21, 2026
MoonFuji Credited to MoonFuji
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem
TypeORM: migration:generate template-literal code injection Moderate
GHSA-2rp8-mm9q-fp49 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface High
CVE-2026-20779 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Kript0r3x Credited to Kript0r3x
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Moderate
CVE-2026-58429 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Pcat2003 Credited to Pcat2003
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata Moderate
CVE-2026-59765 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tikket1 Credited to tikket1, Letian-aarch64, JebeenLee, JLLeitschuh, pick, and kdalal-vulncheck Letian-aarch64 Letian-aarch64
JebeenLee JebeenLee JLLeitschuh JLLeitschuh pick pick kdalal-vulncheck kdalal-vulncheck
Gitea: Webhook Authorization Header Returned in Plaintext via API Low
CVE-2026-58511 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs Moderate
CVE-2026-57897 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Public-only API token restriction is not enforced on team API routes Moderate
CVE-2026-58431 was published for gitea.dev (Go) Jul 21, 2026
rmb122 Credited to rmb122
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 Moderate
CVE-2026-58427 was published for gitea.dev (Go) Jul 21, 2026
Razzlemouse Credited to Razzlemouse
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
Gitea: Notification API leaks private issue metadata after access revocation High
CVE-2026-58419 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Unauthorized Access to Labels of Private Organizations High
CVE-2026-25038 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write High
CVE-2026-27775 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private High
CVE-2026-24451 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
ProTip! Advisories are also available from the GraphQL API