Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

167 advisories

Loading
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet Critical
CVE-2026-90711 was published for proxy-addr (npm) Oct 5, 2026
kagebunsher Credited to kagebunsher, UlisesGascon, and kustundag UlisesGascon UlisesGascon
kustundag kustundag
euriconicacio Credited to euriconicacio
PhucQuan Credited to PhucQuan
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement High
CVE-2026-61672 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
5ud0er Credited to 5ud0er
OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the... Moderate Unreviewed
CVE-2026-56101 was published Sep 8, 2026
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in... High Unreviewed
CVE-2026-67207 was published Jul 30, 2026
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities High
CVE-2026-55771 was published for com.cedarpolicy:cedar-java (Maven) Jul 28, 2026
tomasilluminati Credited to tomasilluminati and laurie-tyz laurie-tyz laurie-tyz
therawdev Credited to therawdev
js-toml has silent type confusion via falsy-primitive duplicate-key bypass Moderate
CVE-2026-50029 was published for js-toml (npm) Jun 26, 2026
CosmicCrusader23 Credited to CosmicCrusader23 and krotname krotname krotname
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers High
CVE-2026-48032 was published for @hulumi/policies (npm) Jun 10, 2026
kerberosmansour Credited to kerberosmansour
ProTip! Advisories are also available from the GraphQL API