Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23 advisories

Loading
WsgiDAV MySQL provider has a blind SQL injection High
CVE-2026-55509 was published for WsgiDAV (pip) Aug 28, 2026
Jvr2022 Credited to Jvr2022
DeepmergeTS has stack exhaustion when merging recursive object graphs High
CVE-2026-40345 was published for deepmerge-ts (npm) Aug 17, 2026
Jvr2022 Credited to Jvr2022
node-tar: Decompression/parse DoS via unlimited input Critical
CVE-2026-59873 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
node-tar: Negative tar entry size causes infinite loop in archive replace High
CVE-2026-59874 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers High
GHSA-j8v8-g9cx-5qf4 was published for @better-auth/scim (npm) Jul 7, 2026
Jvr2022 Credited to Jvr2022
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced High
CVE-2026-48815 was published for sigstore (npm) Jul 1, 2026
Jvr2022 Credited to Jvr2022, Str1ckl4nd, and Zyy0530 Str1ckl4nd Str1ckl4nd
Zyy0530 Zyy0530
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE Moderate
GHSA-wxw3-q3m9-c3jr was published for better-auth (npm) May 15, 2026
Jvr2022 Credited to Jvr2022 and alavesa alavesa alavesa
fast-uri vulnerable to host confusion via percent-encoded authority delimiters High
CVE-2026-6322 was published for fast-uri (npm) May 8, 2026
Jvr2022 Credited to Jvr2022, mcollina, UlisesGascon, climba03003, zakaryan2004, and jlang-ih mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003 zakaryan2004 zakaryan2004 jlang-ih jlang-ih
fast-uri vulnerable to path traversal via percent-encoded dot segments High
CVE-2026-6321 was published for fast-uri (npm) May 8, 2026
Jvr2022 Credited to Jvr2022, mcollina, UlisesGascon, climba03003, zakaryan2004, and jlang-ih mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003 zakaryan2004 zakaryan2004 jlang-ih jlang-ih
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests Moderate
CVE-2026-44456 was published for hono (npm) May 6, 2026
lalalala5678 Credited to lalalala5678 and Jvr2022 Jvr2022 Jvr2022
quarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operations Moderate
CVE-2026-42333 was published for io.quarkiverse.openapi.generator:quarkus-openapi-generator (Maven) May 4, 2026
Jvr2022 Credited to Jvr2022 and ricardozanini ricardozanini ricardozanini
xmldom: Uncontrolled recursion in XML serialization leads to DoS High
CVE-2026-41673 was published for @xmldom/xmldom (npm) Apr 22, 2026
Jvr2022 Credited to Jvr2022, praveen-kv, and KarimTantawey praveen-kv praveen-kv
KarimTantawey KarimTantawey
xmldom has XML node injection through unvalidated comment serialization High
CVE-2026-41672 was published for @xmldom/xmldom (npm) Apr 22, 2026
Jvr2022 Credited to Jvr2022 and TharVid TharVid TharVid
Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME High
CVE-2026-41211 was published for vite-plus (npm) Apr 16, 2026
Jvr2022 Credited to Jvr2022
In monetr, unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation High
CVE-2026-40481 was published for github.com/monetr/monetr (Go) Apr 14, 2026
Jvr2022 Credited to Jvr2022, th3fallen, and elliotcourant th3fallen th3fallen
elliotcourant elliotcourant
unhead: Streaming SSR `streamKey` injected into inline script without identifier validation Low
GHSA-x7mm-9vvv-64w8 was published for unhead (npm) Apr 10, 2026
Jvr2022 Credited to Jvr2022
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates High
CVE-2026-35525 was published for liquidjs (npm) Apr 8, 2026
Jvr2022 Credited to Jvr2022
@stablelib/cbor: Stack exhaustion Denial of Service via deeply nested CBOR arrays, maps, or tags High
GHSA-5jg4-p4qw-cgfr was published for @stablelib/cbor (npm) Apr 4, 2026
Jvr2022 Credited to Jvr2022
@stablelib/cbor: Prototype poisoning via `__proto__` map keys in CBOR decoding High
GHSA-w48f-fwg7-ww6p was published for @stablelib/cbor (npm) Apr 4, 2026
Jvr2022 Credited to Jvr2022
node-tar Symlink Path Traversal via Drive-Relative Linkpath High
CVE-2026-31802 was published for tar (npm) Mar 10, 2026
Jvr2022 Credited to Jvr2022
tar has Hardlink Path Traversal via Drive-Relative Linkpath High
CVE-2026-29786 was published for tar (npm) Mar 5, 2026
Jvr2022 Credited to Jvr2022
@isaacs/brace-expansion has Uncontrolled Resource Consumption High
CVE-2026-25547 was published for @isaacs/brace-expansion (npm) Feb 3, 2026
Jvr2022 Credited to Jvr2022 and intrigus-lgtm intrigus-lgtm intrigus-lgtm
Jvr2022 Credited to Jvr2022
ProTip! Advisories are also available from the GraphQL API