Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

14,654 advisories

Loading
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
GHSA-9mqv-5hh9-4cgg was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem
TypeORM: migration:generate template-literal code injection Moderate
GHSA-2rp8-mm9q-fp49 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Moderate
CVE-2026-58429 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Pcat2003 Credited to Pcat2003
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata Moderate
CVE-2026-59765 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tikket1 Credited to tikket1, Letian-aarch64, JebeenLee, JLLeitschuh, pick, and kdalal-vulncheck Letian-aarch64 Letian-aarch64
JebeenLee JebeenLee JLLeitschuh JLLeitschuh pick pick kdalal-vulncheck kdalal-vulncheck
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs Moderate
CVE-2026-57897 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Public-only API token restriction is not enforced on team API routes Moderate
CVE-2026-58431 was published for gitea.dev (Go) Jul 21, 2026
rmb122 Credited to rmb122
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 Moderate
CVE-2026-58427 was published for gitea.dev (Go) Jul 21, 2026
Razzlemouse Credited to Razzlemouse
Gitea SSH Key Parser Denial of Service Moderate
CVE-2026-56657 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea LFS Deploy-Key Privilege Escalation Moderate
CVE-2026-58435 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Local File Inclusion via file:// URI in Migration Restore Moderate
CVE-2026-58420 was published for gitea.dev (Go) Jul 21, 2026
isa0-gh Credited to isa0-gh and ibrahmsql ibrahmsql ibrahmsql
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes Moderate
CVE-2026-55982 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: REST API exposes organization membership of private organizations to public Moderate
CVE-2026-58417 was published for gitea.dev (Go) Jul 21, 2026
maluff Credited to maluff, Sai2r, and mgelde Sai2r Sai2r
mgelde mgelde
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) Moderate
CVE-2026-50105 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
CassianStarck Credited to CassianStarck
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint Moderate
CVE-2026-42931 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Tricta Credited to Tricta
StarPlatinu Credited to StarPlatinu
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass Moderate
CVE-2026-58442 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Tomer-PL Credited to Tomer-PL
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL Moderate
CVE-2026-58441 was published for code.gitea.io/gitea (Go) Jul 21, 2026
yoojoon2 Credited to yoojoon2
Gitea: SSRF via HTTP Redirect in Repository Migration Moderate
CVE-2026-58418 was published for code.gitea.io/gitea (Go) Jul 21, 2026
moltenbit Credited to moltenbit
babakizo420 Credited to babakizo420
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions Moderate
GHSA-rjvx-x5h2-6px5 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
ProTip! Advisories are also available from the GraphQL API