Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,385 advisories

Loading
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact` Moderate
GHSA-jrpc-7vxp-69p6 was published for org.http4k:http4k-core (Maven) Jun 19, 2026
massif-01 Credited to massif-01
JLine: ReDoS in Nano Editor Regex Search Mode Moderate
CVE-2026-77421 was published for org.jline:jline-builtins (Maven) Sep 23, 2026
sectroyer Credited to sectroyer
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable Moderate
CVE-2026-77420 was published for org.jline:jline-reader (Maven) Sep 23, 2026
sectroyer Credited to sectroyer
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers Moderate
CVE-2026-65829 was published for MPXJ.Net (RubyGems) Sep 22, 2026
czTangt Credited to czTangt
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion Moderate
CVE-2026-48043 was published for io.netty:netty-codec-http2 (Maven) Jun 11, 2026
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target Moderate
CVE-2026-85717 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request Moderate
CVE-2026-85720 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth Moderate
CVE-2026-73245 was published for io.kestra:kestra (Maven) Sep 17, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators Moderate
CVE-2026-69201 was published for org.http4s:http4s-server_2.12 (Maven) Sep 15, 2026
Lasering Credited to Lasering, rossabaker, and samspills rossabaker rossabaker
samspills samspills
Http4s: Ember chunk parser lenience (TE.TE request smuggling) Moderate
CVE-2026-69216 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII, rossabaker, and morgen-peschke rossabaker rossabaker
morgen-peschke morgen-peschke
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin Moderate
CVE-2026-69215 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, ERobertGII, and samspills ERobertGII ERobertGII
samspills samspills
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain Moderate
CVE-2026-69214 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Http4s: DigestAuth allows replay of captured requests Moderate
CVE-2026-69206 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker and morgen-peschke morgen-peschke morgen-peschke
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL Moderate
CVE-2026-44913 was published for org.apache.nifi:nifi-cdc-mysql-processors (Maven) Jun 22, 2026
Apache NiFi fails to validate proxy host headers when constructing qualified URLs Moderate
CVE-2026-54665 was published for org.apache.nifi:nifi-jetty (Maven) Jun 22, 2026
Apache Atlas UI: Authenticated User XSS Moderate
CVE-2025-62198 was published for org.apache.atlas:atlas-dashboardv2 (Maven) Jun 22, 2026
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion Moderate
CVE-2026-11748 was published for com.linecorp.centraldogma:centraldogma-server-auth-shiro (Maven) Sep 11, 2026
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing Moderate
CVE-2026-75596 was published for io.netty:netty-handler (Maven) Sep 8, 2026
mauriceng98 Credited to mauriceng98
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification Moderate
GHSA-248h-974q-xrc2 was published for com.getaxonflow:axonflow-sdk (Maven) May 6, 2026
massif-01 Credited to massif-01
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
CVE-2026-18401 was published for com.fasterxml.jackson.core:jackson-core (Maven) Feb 28, 2026
sprabhav7 Credited to sprabhav7, rohan-repos, neilmadden-hazelcast, awsactran, cowtowncoder, and anthonydahanne rohan-repos rohan-repos
neilmadden-hazelcast neilmadden-hazelcast awsactran awsactran cowtowncoder cowtowncoder anthonydahanne anthonydahanne
Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition Moderate
GHSA-6qm2-mcq7-53qp was published for tools.jackson.core:jackson-core (Maven) Aug 4, 2026 • withdrawn
Apache Tomcat - Client certificate verification bypass Moderate
CVE-2025-66614 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Feb 17, 2026
Jenson3210 Credited to Jenson3210, yusuke-koyoshi, and sealbenb yusuke-koyoshi yusuke-koyoshi
sealbenb sealbenb
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
ProTip! Advisories are also available from the GraphQL API