Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

132,098 advisories

Loading
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override High
CVE-2026-54481 was published for code.gitea.io/gitea (Go) Jul 21, 2026
sanil18 Credited to sanil18
Gitea: Permanent Fork PR Workflow Approval Gate Bypass High
CVE-2026-58424 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Tomer-PL Credited to Tomer-PL
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects High
CVE-2026-28740 was published for gitea.dev (Go) Jul 21, 2026
m2hcz Credited to m2hcz
Gitea: Privilege Escalation via Access Token Scope Escalation in API High
CVE-2026-56654 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz and ohxorud-dev ohxorud-dev ohxorud-dev
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag High
CVE-2026-58439 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yonatan-pl Credited to yonatan-pl
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist High
GHSA-2f96-g7mh-g2hx was published for GitPython (pip) Jul 21, 2026
hackkim Credited to hackkim and abhiprd2000 abhiprd2000 abhiprd2000
GitPython unsafe clone option gate bypass through joined short options High
GHSA-v396-v7q4-x2qj was published for GitPython (pip) Jul 21, 2026
Faze-up Credited to Faze-up
SVGO removeScripts plugin leaves some executable scripts intact High
GHSA-2p49-hgcm-8545 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
cyberlanc3r Credited to cyberlanc3r
pyasn1: Uncontrolled resource consumption when converting decoded REAL values High
CVE-2026-59886 was published for pyasn1 (pip) Jul 21, 2026
gvozdila Credited to gvozdila
tynus2 Credited to tynus2
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs High
CVE-2026-59884 was published for pyssn1 (pip) Jul 21, 2026
mikeappsec Credited to mikeappsec
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header High
CVE-2026-59892 was published for @opentelemetry/propagator-jaeger (npm) Jul 21, 2026
EQSTLab Credited to EQSTLab and pichlermarc pichlermarc pichlermarc
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text High
CVE-2026-59887 was published for linkify-it (npm) Jul 21, 2026
bibu123456 Credited to bibu123456 and Kayiz-PT Kayiz-PT Kayiz-PT
aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling High
CVE-2026-13760 was published for aws-cdk-lib (npm) Jul 21, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization High
CVE-2026-13676 was published for fast-uri (npm) Jul 21, 2026
celinke97 Credited to celinke97 and UlisesGascon UlisesGascon UlisesGascon
Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth
Immutable.js `List` 32-bit trie overflow → unrecoverable DoS High
CVE-2026-59879 was published for immutable (npm) Jul 21, 2026
mateuszismyname Credited to mateuszismyname
websocket-driver-ruby: Denial of service via malformed Host header High
CVE-2026-61666 was published for websocket-driver (RubyGems) Jul 21, 2026
pranjalithakur Credited to pranjalithakur
ProTip! Advisories are also available from the GraphQL API