Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

724 advisories

Loading
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout Moderate
CVE-2026-107804 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
lujiefsi Credited to lujiefsi
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment Critical
CVE-2026-108261 was published for @tinacms/app (npm) Oct 9, 2026
sondt99 Credited to sondt99
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header High
CVE-2026-61435 was published for praisonai (pip) Oct 8, 2026
rexpository Credited to rexpository
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins High
CVE-2026-107230 was published for org.asynchttpclient:async-http-client (Maven) Oct 8, 2026
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass Moderate
CVE-2026-94485 was published for next (npm) Oct 7, 2026
Payload external upload trust validation issue High
CVE-2026-105861 was published for payload (npm) Oct 7, 2026
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path Critical
CVE-2026-103922 was published for @capacitor/android (Maven) Oct 5, 2026
andredestro Credited to andredestro
alham-rizvi Credited to alham-rizvi
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors High
CVE-2026-85152 was published for undici (npm) Sep 29, 2026
nikolakojic-rasit Credited to nikolakojic-rasit, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab High
CVE-2026-102673 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled High
CVE-2026-102675 was published for electron (npm) Sep 29, 2026
manus-use Credited to manus-use
ProTip! Advisories are also available from the GraphQL API