Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13,406 advisories

Loading
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination Moderate
CVE-2026-48484 was published for pyload-ng (pip) Oct 9, 2026
pevinkumar10 Credited to pevinkumar10
Hazelcast allows arbitrary member memory access by low-privileged client Critical
CVE-2026-107726 was published for com.hazelcast:hazelcast (Maven) Oct 8, 2026
k-jamroz Credited to k-jamroz
Banks: User-controlled prompt input can be parsed as privileged chat messages Moderate
CVE-2026-107717 was published for banks (pip) Oct 8, 2026
swordmein Credited to swordmein
Char0n1507 Credited to Char0n1507
dinhvaren Credited to dinhvaren
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection Moderate
GHSA-w253-m66g-rx24 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules Moderate
GHSA-3wr7-993q-jrff was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
airween Credited to airween and janmrow janmrow janmrow
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection Moderate
GHSA-5gj4-9gm7-2fx2 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml Moderate
CVE-2026-107225 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE High
CVE-2026-106443 was published for WeasyPrint (pip) Oct 7, 2026
svinkros Credited to svinkros
Backstage: Improper entity validation in deprecated Kubernetes services endpoint Moderate
CVE-2026-106563 was published for @backstage/plugin-kubernetes-backend (npm) Oct 7, 2026
Backstage: Improper input validation in proxy-backend Moderate
CVE-2026-106491 was published for @backstage/plugin-proxy-backend (npm) Oct 7, 2026
ProTip! Advisories are also available from the GraphQL API