Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,246 advisories

Loading
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation Moderate
CVE-2026-59882 was published for guzzlehttp/psr7 (Composer) Jul 21, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: URI fragments disclosed in redirect Referer headers Moderate
GHSA-h95v-h523-3mw8 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Host-only cookie scope is not preserved Moderate
GHSA-wm3w-8rrp-j577 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-f283-ghqc-fg79 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Cookie Disclosure and Injection via IP-Address Domains Moderate
CVE-2026-59883 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files Moderate
CVE-2026-59946 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) Moderate
CVE-2026-59947 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-94pj-82f3-465w was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Composer: Arbitrary file write outside vendor via malicious transitive package name High
CVE-2026-59948 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration Moderate
GHSA-cvpc-hccg-wmw4 was published for verbb/formie (Composer) Jul 17, 2026
chaitanyagarware Credited to chaitanyagarware
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise Critical
CVE-2026-55579 was published for pheditor/pheditor (Composer) Jul 16, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
Pheditor has an authenticated terminal command whitelist bypass High
CVE-2026-54540 was published for pheditor/pheditor (Composer) Jul 16, 2026
shanjijian Credited to shanjijian
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files Moderate
GHSA-xg43-5579-qw6v was published for adawolfa/isdoc (Composer) Jul 15, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php High
CVE-2026-62944 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dracosectech-code Credited to dracosectech-code and dregad dregad dregad
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs Moderate
CVE-2026-52883 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
byteoverride Credited to byteoverride and dregad dregad dregad
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters Moderate
CVE-2026-52882 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dregad Credited to dregad
MantisBT: Reflected XSS in admin/install.php via unescaped printf Critical
CVE-2026-52881 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
MantisBT: Reflected XSS in admin/install.php Critical
CVE-2026-52847 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail Moderate
CVE-2026-50552 was published for phanan/koel (Composer) Jul 15, 2026
Yunkaiwjs Credited to Yunkaiwjs
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths High
CVE-2026-54491 was published for phanan/koel (Composer) Jul 15, 2026
kiffa-australis256 Credited to kiffa-australis256
Koel has SSRF through Authenticated Subsonic podcast feed URLs Moderate
GHSA-8q6q-m837-fv64 was published for phanan/koel (Composer) Jul 15, 2026
DavidCarliez Credited to DavidCarliez
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations High
CVE-2026-54493 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation Moderate
CVE-2026-54492 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
ProTip! Advisories are also available from the GraphQL API