Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

19 advisories

Loading
ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer High
CVE-2026-106115 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
ImageSharp: EXR ZIP decoder can expose stale allocator data after a short inflate Moderate
CVE-2026-106111 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
ImageSharp: ICC LUT16 output channel count can write beyond Vector4 High
CVE-2026-106112 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing loop Moderate
CVE-2026-106116 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer High
CVE-2026-106110 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
ImageSharp: HistogramEqualization uses an unvalidated luminance as an unchecked histogram index High
CVE-2026-106113 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dimensions Moderate
CVE-2026-106114 was published for SixLabors.ImageSharp (NuGet) Oct 7, 2026
MegaManSec Credited to MegaManSec
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
undici vulnerable to caching and replay of unsafe HTTP method responses Low
CVE-2026-85008 was published for undici (npm) Sep 29, 2026
MegaManSec Credited to MegaManSec, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
OpenEXR has use after free in PyObject_StealAttrString Moderate
CVE-2025-64183 was published for OpenEXR (pip) Apr 6, 2026
MegaManSec Credited to MegaManSec
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel() Moderate
CVE-2025-64182 was published for OpenEXR (pip) Apr 6, 2026
MegaManSec Credited to MegaManSec
OpenClaw has a command injection in maintainer clawtributors updater High
CVE-2026-26323 was published for openclaw (npm) Feb 18, 2026
scanleale Credited to scanleale and MegaManSec MegaManSec MegaManSec
MegaManSec Credited to MegaManSec
simecek Credited to simecek, stanislavfortaisle, and MegaManSec stanislavfortaisle stanislavfortaisle
MegaManSec MegaManSec
Nextcloud Talk allowlist bypass via actor.name display name spoofing Critical
CVE-2026-28474 was published for @openclaw/nextcloud-talk (npm) Feb 17, 2026
MegaManSec Credited to MegaManSec
OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching Moderate
CVE-2026-28471 was published for openclaw (npm) Feb 17, 2026
MegaManSec Credited to MegaManSec
OpenClaw BlueBubbles webhook auth bypass via loopback proxy trust High
CVE-2026-26316 was published for @openclaw/bluebubbles (npm) Feb 17, 2026
MegaManSec Credited to MegaManSec
Improper Validation of Query Parameters in Auth0 Next.js SDK Low
CVE-2025-67716 was published for @auth0/nextjs-auth0 (npm) Dec 10, 2025
MegaManSec Credited to MegaManSec
Improper Request Caching Lookup in the Auth0 Next.js SDK Moderate
CVE-2025-67490 was published for @auth0/nextjs-auth0 (npm) Dec 10, 2025
MegaManSec Credited to MegaManSec
ProTip! Advisories are also available from the GraphQL API