Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

80 advisories

Loading
etcd: Watch API authorization bypass via open-ended range requests High
GHSA-xg4h-6gfc-h4m8 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
Gitea SSH Key Parser Denial of Service Moderate
CVE-2026-56657 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea: Privilege Escalation via Access Token Scope Escalation in API High
CVE-2026-56654 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz and ohxorud-dev ohxorud-dev ohxorud-dev
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload High
CVE-2026-56755 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Gitea Remember-Me Token Theft Not Invalidating Attacker Session Critical
CVE-2026-56750 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret Moderate
CVE-2025-61926 was published for github.com/ossf/allstar (Go) Oct 10, 2025
AdamKorcz Credited to AdamKorcz and justaugustus justaugustus justaugustus
PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion Low
CVE-2025-48059 was published for com.powsybl:powsybl-contingency-api (Maven) Jun 19, 2025
arthurscchan Credited to arthurscchan, AdamKorcz, rolnico, and olperr1 AdamKorcz AdamKorcz
rolnico rolnico olperr1 olperr1
PowSyBl Core contains Polynomial REDoS’es Moderate
CVE-2025-48058 was published for com.powsybl:powsybl-commons (Maven) Jun 19, 2025
arthurscchan Credited to arthurscchan, AdamKorcz, rolnico, and olperr1 AdamKorcz AdamKorcz
rolnico rolnico olperr1 olperr1
PowSyBl Core allows deserialization of untrusted SparseMatrix data High
CVE-2025-47771 was published for com.powsybl:powsybl-math (Maven) Jun 19, 2025
arthurscchan Credited to arthurscchan, AdamKorcz, olperr1, and rolnico AdamKorcz AdamKorcz
olperr1 olperr1 rolnico rolnico
PowSyBl Core XML Reader allows XXE and SSRF Low
CVE-2025-47293 was published for com.powsybl:powsybl-commons (Maven) Jun 19, 2025
AdamKorcz Credited to AdamKorcz, arthurscchan, rolnico, and olperr1 arthurscchan arthurscchan
rolnico rolnico olperr1 olperr1
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin High
CVE-2025-32777 was published for volcano.sh/volcano (Go) Apr 30, 2025
kevin-wangzefeng Credited to kevin-wangzefeng, Monokaix, and AdamKorcz Monokaix Monokaix
AdamKorcz AdamKorcz
tough cyclic delegation graphs are not detected Low
GHSA-j8x2-777p-23fc was published for tough (Rust) Mar 28, 2025
jku Credited to jku and AdamKorcz AdamKorcz AdamKorcz
tough terminating targets role delegations are not respected Moderate
CVE-2025-2886 was published for tough (Rust) Mar 28, 2025
jku Credited to jku and AdamKorcz AdamKorcz AdamKorcz
tough root metadata version is not checked for sequential versioning Moderate
CVE-2025-2885 was published for tough (Rust) Mar 28, 2025
jku Credited to jku and AdamKorcz AdamKorcz AdamKorcz
tough timestamp metadata is cached when it fails snapshot rollback check Moderate
CVE-2025-2888 was published for tough (Rust) Mar 28, 2025
jku Credited to jku and AdamKorcz AdamKorcz AdamKorcz
tough failure to detect delegated target rollback Moderate
CVE-2025-2887 was published for tough (Rust) Mar 28, 2025
jku Credited to jku and AdamKorcz AdamKorcz AdamKorcz
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity High
CVE-2024-10270 was published for org.keycloak:keycloak-services (Maven) Nov 25, 2024
AdamKorcz Credited to AdamKorcz
Incorrect delegation lookups can make go-tuf download the wrong artifact High
CVE-2024-47534 was published for github.com/theupdateframework/go-tuf/v2 (Go) Oct 1, 2024
AdamKorcz Credited to AdamKorcz and mamccorm mamccorm mamccorm
basic-auth-connect's callback uses time unsafe string comparison High
CVE-2024-47178 was published for basic-auth-connect (npm) Sep 30, 2024
UlisesGascon Credited to UlisesGascon, ctcpip, AdamKorcz, and blakeembrey ctcpip ctcpip
AdamKorcz AdamKorcz blakeembrey blakeembrey
send vulnerable to template injection that can lead to XSS Low
CVE-2024-43799 was published for send (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
serve-static vulnerable to template injection that can lead to XSS Low
CVE-2024-43800 was published for serve-static (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
express vulnerable to XSS via response.redirect() Low
CVE-2024-43796 was published for express (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
body-parser vulnerable to denial of service when url encoding is enabled High
CVE-2024-45590 was published for body-parser (npm) Sep 10, 2024
AdamKorcz Credited to AdamKorcz, UlisesGascon, ctcpip, and wesleytodd UlisesGascon UlisesGascon
ctcpip ctcpip wesleytodd wesleytodd
sigstore-go has an unbounded loop over untrusted input can lead to endless data attack Low
CVE-2024-45395 was published for github.com/sigstore/sigstore-go (Go) Sep 4, 2024
AdamKorcz Credited to AdamKorcz and codysoyland codysoyland codysoyland
ProTip! Advisories are also available from the GraphQL API