Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

895 advisories

Loading
Apache Polaris has an Improper Input Validation Issue Critical
CVE-2026-42810 was published for org.apache.polaris:polaris-core (Maven) May 4, 2026
Apache Polaris has an Improper Input Validation Issue Critical
CVE-2026-42809 was published for org.apache.polaris:polaris-runtime-service (Maven) May 4, 2026
Apache Polaris has an Improper Input Validation issue Critical
CVE-2026-42812 was published for org.apache.polaris:polaris-runtime-service (Maven) May 4, 2026
Apache Polaris has an Improper Input Validation issue Critical
CVE-2026-42811 was published for org.apache.polaris:polaris-core (Maven) May 4, 2026
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing Critical
CVE-2026-40682 was published for org.apache.opennlp:opennlp-tools (Maven) May 4, 2026
OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip) Critical
CVE-2026-40076 was published for org.openmrs.web:openmrs-web (Maven) May 4, 2026
Arron-bit Credited to Arron-bit
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix) Critical
CVE-2026-42779 was published for org.apache.mina:mina-core (Maven) May 1, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix) Critical
CVE-2026-42778 was published for org.apache.mina:mina-core (Maven) May 1, 2026
Shopizer has a path traversal issue Critical
CVE-2026-36767 was published for com.shopizer:shopizer (Maven) Apr 30, 2026
fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE Critical
CVE-2026-41586 was published for org.hyperledger.fabric-sdk-java:fabric-sdk-java (Maven) Apr 29, 2026
brodmart Credited to brodmart
Jenkins GitHub Plugin has an XSS vulnerability Critical
CVE-2026-42523 was published for org.jenkins-ci.plugins:git (Maven) Apr 29, 2026
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health Critical
CVE-2026-40976 was published for org.springframework.boot:spring-boot (Maven) Apr 28, 2026
Apache Camel's Camel-Mail component is vulnerable to Camel message header injection Critical
CVE-2026-33454 was published for org.apache.camel:camel-mail (Maven) Apr 27, 2026
Apache camel-coap allows header injection that can lead to remote code execution Critical
CVE-2026-33453 was published for org.apache.camel:camel-coap (Maven) Apr 27, 2026
Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix) Critical
CVE-2026-41409 was published for org.apache.mina:mina-core (Maven) Apr 27, 2026
Apache MINA vulnerable to Deserialization of Untrusted Data Critical
CVE-2026-41635 was published for org.apache.mina:mina-core (Maven) Apr 27, 2026
Apache Camel has an incomplete fix for CVE-2025-27636 Critical
CVE-2026-40453 was published for org.apache.camel:camel-coap (Maven) Apr 27, 2026
kmagdziarz Credited to kmagdziarz
Spinnaker: RCE via expression parsing due to unrestricted context handling Critical
CVE-2026-32613 was published for io.spinnaker.echo:echo-pipelinetriggers (Maven) Apr 21, 2026
LeftenantZero Credited to LeftenantZero and jasonmcintosh jasonmcintosh jasonmcintosh
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths Critical
CVE-2026-32604 was published for io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo (Maven) Apr 21, 2026
LeftenantZero Credited to LeftenantZero and jasonmcintosh jasonmcintosh jasonmcintosh
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation Critical
CVE-2026-33557 was published for org.apache.kafka:kafka-clients (Maven) Apr 20, 2026
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf Critical
CVE-2026-40478 was published for org.thymeleaf:thymeleaf (Maven) Apr 15, 2026
Improper restriction of the scope of accessible objects in Thymeleaf expressions Critical
CVE-2026-40477 was published for org.thymeleaf:thymeleaf (Maven) Apr 15, 2026
Expression Injection in OpenRemote Critical
CVE-2026-39842 was published for io.openremote:openremote-manager (Maven) Apr 14, 2026
qxyuan853 Credited to qxyuan853
Apache Tomcat: CLIENT_CERT authentication does not fail as expected Critical
CVE-2026-29145 was published for org.apache.tomcat:tomcat (Maven) Apr 9, 2026
aruneko Credited to aruneko
Emissary has GitHub Actions Shell Injection via Workflow Inputs Critical
CVE-2026-35580 was published for gov.nsa.emissary:emissary (Maven) Apr 8, 2026
BrennanTM Credited to BrennanTM
ProTip! Advisories are also available from the GraphQL API