Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,277 advisories

Loading
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields Low
CVE-2026-4053 was published for github.com/mattermost/mattermost-server (Go) May 15, 2026
qi-scape Credited to qi-scape and Classic298 Classic298 Classic298
Strapi: Password Reset Does Not Revoke Existing Refresh Sessions Low
CVE-2026-22706 was published for @strapi/admin (npm) May 13, 2026
zaddy6 Credited to zaddy6, arthurgervais, derrickmehaffy, AndyAnh174, and Aastha2602 arthurgervais arthurgervais
derrickmehaffy derrickmehaffy AndyAnh174 AndyAnh174 Aastha2602 Aastha2602
Astro: Server island encrypted parameters vulnerable to cross-component replay Low
CVE-2026-45028 was published for astro (npm) May 13, 2026
Popax21 Credited to Popax21
Apache Tomcat - AJP secret compared in non-constant time Low
CVE-2026-43514 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) May 12, 2026
omec-project amf crashes when processing malformed LocationReports Low
CVE-2026-8349 was published for github.com/omec-project/amf (Go) May 12, 2026
cowlib: Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1 Low
CVE-2026-43969 was published for cowlib (Erlang) May 11, 2026
Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints Low
GHSA-w626-296m-8f85 was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners Low
GHSA-p3pv-c954-9m6f was published for openclaw (npm) May 11, 2026 withdrawn
Next.js's Middleware / Proxy redirects can be cache-poisoned Low
CVE-2026-44572 was published for next (npm) May 11, 2026
Ella Core has handover failures during concurrent Security Mode Command Low
CVE-2026-44474 was published for github.com/ellanetworks/core (Go) May 11, 2026
SJNA0414 Credited to SJNA0414, ICSR-KMU, and bradypus404 ICSR-KMU ICSR-KMU
bradypus404 bradypus404
bettercap Has an Integer Coercion Error in modules/mysql_server/mysql_server.go Low
CVE-2026-8276 was published for github.com/bettercap/bettercap/v2 (Go) May 11, 2026
bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function Low
CVE-2026-8275 was published for github.com/bettercap/bettercap/v2 (Go) May 11, 2026
OSGeo gdal has a heap-based buffer overflow Low
CVE-2026-8212 was published for GDAL (pip) May 10, 2026
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() Low
CVE-2026-44459 was published for hono (npm) May 9, 2026
AdmirBajric Credited to AdmirBajric
absinthe_plug Has a Cross-site Scripting vulnerability Low
CVE-2026-42794 was published for absinthe_plug (Erlang) May 8, 2026
justhtml introduces denial-of-service hardening Low
GHSA-r8cj-3554-33mr was published for justhtml (pip) May 8, 2026
EmilStenstrom Credited to EmilStenstrom
nhost has Session Persistence After Password Change Low
GHSA-7hgr-xvrr-xpw3 was published for github.com/nhost/nhost (Go) May 8, 2026
skoveit Credited to skoveit
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience Low
CVE-2026-44428 was published for github.com/modelcontextprotocol/registry (Go) May 8, 2026
FORIMOC Credited to FORIMOC, Yuremin, and rdimitrov Yuremin Yuremin
rdimitrov rdimitrov
OSGeo GDAL vulnerable to out-of-bounds read Low
CVE-2026-8088 was published for GDAL (pip) May 7, 2026
OSGeo GDAL vulnerable to heap-based buffer overflow Low
CVE-2026-8087 was published for GDAL (pip) May 7, 2026
Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy Low
GHSA-h4fw-6r7f-w494 was published for web-auth/webauthn-framework (Composer) May 7, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API