Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

164,411 advisories

Loading
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
GHSA-9mqv-5hh9-4cgg was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem
TypeORM: migration:generate template-literal code injection Moderate
GHSA-2rp8-mm9q-fp49 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Moderate
CVE-2026-58429 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Pcat2003 Credited to Pcat2003
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata Moderate
CVE-2026-59765 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tikket1 Credited to tikket1, Letian-aarch64, JebeenLee, JLLeitschuh, pick, and kdalal-vulncheck Letian-aarch64 Letian-aarch64
JebeenLee JebeenLee JLLeitschuh JLLeitschuh pick pick kdalal-vulncheck kdalal-vulncheck
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs Moderate
CVE-2026-57897 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Public-only API token restriction is not enforced on team API routes Moderate
CVE-2026-58431 was published for gitea.dev (Go) Jul 21, 2026
rmb122 Credited to rmb122
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 Moderate
CVE-2026-58427 was published for gitea.dev (Go) Jul 21, 2026
Razzlemouse Credited to Razzlemouse
djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in... Moderate Unreviewed
CVE-2026-64822 was published Jul 21, 2026
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure... Moderate Unreviewed
CVE-2026-63092 was published Jul 21, 2026
Tanium addressed an information disclosure vulnerability in Connect. Moderate Unreviewed
CVE-2026-12139 was published Jul 21, 2026
ProTip! Advisories are also available from the GraphQL API