Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

386 advisories

Loading
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout Moderate
CVE-2026-107804 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
lujiefsi Credited to lujiefsi
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass Moderate
CVE-2026-94485 was published for next (npm) Oct 7, 2026
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools Moderate
CVE-2026-77339 was published for github.com/f1bonacc1/process-compose (Go) Sep 18, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Moderate
CVE-2026-67448 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
arpitjain099 Credited to arpitjain099
ProTip! Advisories are also available from the GraphQL API