Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,410 advisories

Loading
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist) Moderate
CVE-2026-83557 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
prvazsahnazarov Credited to prvazsahnazarov
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution Moderate
CVE-2026-19032 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
waydeshi Credited to waydeshi
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization Moderate
CVE-2026-77310 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Sep 28, 2026
thientd Credited to thientd and pussycat0x pussycat0x pussycat0x
JLine: ReDoS in Nano Editor Regex Search Mode Moderate
CVE-2026-77421 was published for org.jline:jline-builtins (Maven) Sep 23, 2026
sectroyer Credited to sectroyer
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable Moderate
CVE-2026-77420 was published for org.jline:jline-reader (Maven) Sep 23, 2026
sectroyer Credited to sectroyer
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers Moderate
CVE-2026-65829 was published for MPXJ.Net (RubyGems) Sep 22, 2026
czTangt Credited to czTangt
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target Moderate
CVE-2026-85717 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request Moderate
CVE-2026-85720 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth Moderate
CVE-2026-73245 was published for io.kestra:kestra (Maven) Sep 17, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators Moderate
CVE-2026-69201 was published for org.http4s:http4s-server_2.12 (Maven) Sep 15, 2026
Lasering Credited to Lasering, rossabaker, and samspills rossabaker rossabaker
samspills samspills
Http4s: Ember chunk parser lenience (TE.TE request smuggling) Moderate
CVE-2026-69216 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII, rossabaker, and morgen-peschke rossabaker rossabaker
morgen-peschke morgen-peschke
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin Moderate
CVE-2026-69215 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, ERobertGII, and samspills ERobertGII ERobertGII
samspills samspills
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain Moderate
CVE-2026-69214 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Http4s: DigestAuth allows replay of captured requests Moderate
CVE-2026-69206 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker and morgen-peschke morgen-peschke morgen-peschke
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion Moderate
CVE-2026-11748 was published for com.linecorp.centraldogma:centraldogma-server-auth-shiro (Maven) Sep 11, 2026
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing Moderate
CVE-2026-75596 was published for io.netty:netty-handler (Maven) Sep 8, 2026
mauriceng98 Credited to mauriceng98
fg0x0 Credited to fg0x0
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output Moderate
CVE-2026-55859 was published for org.mariadb:r2dbc-mariadb (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context Moderate
CVE-2026-55858 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55857 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB has cleartext password disclosure to a MITM on the initial-handshake Moderate
CVE-2026-55856 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens Moderate
CVE-2026-55867 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
michaelddickenson Credited to michaelddickenson and sreelim sreelim sreelim
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields Moderate
CVE-2026-55425 was published for org.graylog2:graylog2-server (Maven) Aug 28, 2026
Evelynkaz Credited to Evelynkaz
Yamcs has DOM XSS in Extension Routing Moderate
CVE-2026-55566 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811 and rgfradique rgfradique rgfradique
ProTip! Advisories are also available from the GraphQL API