Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

168 advisories

Loading
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection Moderate
GHSA-w253-m66g-rx24 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules Moderate
GHSA-3wr7-993q-jrff was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
airween Credited to airween and janmrow janmrow janmrow
Coraza has Cookie Parser Confusion Moderate
GHSA-g4qm-m288-5cp9 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
HackingRepo Credited to HackingRepo and fzipi fzipi fzipi
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection Moderate
GHSA-5gj4-9gm7-2fx2 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend High
CVE-2026-106505 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets High
GHSA-9c5c-9qcx-q35q was published for @nestjs/platform-fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization Moderate
CVE-2026-86818 was published for fast-uri (npm) Sep 29, 2026
manus-use Credited to manus-use, mcollina, UlisesGascon, and manus-pi mcollina mcollina
UlisesGascon UlisesGascon manus-pi manus-pi
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing Moderate
GHSA-g57g-f23g-4646 was published for nodemailer (npm) Sep 29, 2026
ZeroXJacks Credited to ZeroXJacks
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content Moderate
GHSA-p634-w6r4-rjp2 was published for adm-zip (npm) Sep 29, 2026
zikk090 Credited to zikk090
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority High
CVE-2026-84394 was published for fast-uri (npm) Sep 28, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict High
CVE-2026-56669 was published for elysia (npm) Sep 23, 2026
jviide Credited to jviide
LMDeploy has an SSRF bypass High
GHSA-39wr-7q6h-cf68 was published for lmdeploy (pip) Sep 18, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and clzoom RacerZ-fighting RacerZ-fighting
clzoom clzoom
Traefik entrypoint header-name sanitization bypassed via request trailers High
CVE-2026-88004 was published for github.com/traefik/traefik/v3 (Go) Sep 10, 2026
bipol4r Credited to bipol4r
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain Moderate
GHSA-wmmp-3585-3rmp was published for nodemailer (npm) Sep 8, 2026
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning Moderate
CVE-2026-73846 was published for @aborruso/ckan-mcp-server (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Mail: Email address spoofing via malformed RFC 2047 encoded-words Moderate
CVE-2026-63435 was published for mail (RubyGems) Sep 2, 2026
mantas Credited to mantas and glefait glefait glefait
ProTip! Advisories are also available from the GraphQL API