Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,015 advisories

Loading
AWS Amplify Studio UI Component Properties Has an Input Validation Issue Critical
CVE-2025-4318 was published for @aws-amplify/codegen-ui-react (npm) Jul 30, 2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing Critical
CVE-2026-66066 was published for activestorage (RubyGems) Jul 30, 2026
0xacb Credited to 0xacb, Ry0taK, flavorjones, jeremy, byroot, ethiack-admin, s3np41k1r1t0, castilho101, and rafaelfranca Ry0taK Ry0taK
flavorjones flavorjones jeremy jeremy byroot byroot ethiack-admin ethiack-admin s3np41k1r1t0 s3np41k1r1t0 castilho101 castilho101 rafaelfranca rafaelfranca
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure Low
CVE-2026-54522 was published for msgpack (RubyGems) Jul 30, 2026
pranjalithakur Credited to pranjalithakur
dssrf has an SSRF bypass with remove_at_symbol_in_string High
CVE-2026-54722 was published for dssrf (npm) Jul 30, 2026
HackingRepo Credited to HackingRepo and andrewmkhoury andrewmkhoury andrewmkhoury
manus-use Credited to manus-use
manus-use Credited to manus-use
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url High
CVE-2026-67425 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted High
CVE-2026-67427 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) Critical
CVE-2026-67429 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect Moderate
CVE-2026-67435 was published for linuxfabrik-lib (pip) Jul 30, 2026
Pig-Tail Credited to Pig-Tail
MCP Ruby SDK: Ruby SSE Session Poisoning High
CVE-2026-67431 was published for mcp (RubyGems) Jul 30, 2026
srikanthramu Credited to srikanthramu
hewei-gikaku Credited to hewei-gikaku
hewei-gikaku Credited to hewei-gikaku
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS) Moderate
CVE-2026-63119 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection Moderate
CVE-2026-63118 was published for mcp (RubyGems) Jul 30, 2026
tonghuaroot Credited to tonghuaroot, dodge1218, and hewei-gikaku dodge1218 dodge1218
hewei-gikaku hewei-gikaku
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check Moderate
CVE-2026-67438 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
Ayantaker Credited to Ayantaker
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output Moderate
CVE-2026-67439 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
offset Credited to offset
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) High
CVE-2026-67437 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
knight-yagami Credited to knight-yagami
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords Moderate
CVE-2026-54704 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
FWinkler79 Credited to FWinkler79
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion Moderate
CVE-2026-54712 was published for io.opentelemetry.javaagent:opentelemetry-javaagent (Maven) Jul 29, 2026
decsecre583 Credited to decsecre583
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal Low
GHSA-pmwx-rm49-xv39 was published for activerecord-tenanted (RubyGems) Jul 29, 2026
tonghuaroot Credited to tonghuaroot
netfoil: Incorrect block responses could lead to localhost traffic High
GHSA-xvg2-cgv6-6h7v was published for github.com/tinfoil-factory/netfoil (Go) Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
ProTip! Advisories are also available from the GraphQL API