Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

114 advisories

Loading
ydb-go-sdk's transactions are not committed using the `options.WithCommit()` option on last call `table.Transaction.Execute` in transaction Low
GHSA-28xx-pppm-vqff was published for github.com/ydb-platform/ydb-go-sdk/v3 (Go) Apr 30, 2026
kprokopenko Credited to kprokopenko and asmyasnikov asmyasnikov asmyasnikov
Duplicate Advisory: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided Low
GHSA-qmq6-f8pr-cx5x was published for uuid (npm) Apr 23, 2026 withdrawn
julianladisch Credited to julianladisch
uutils coreutils has an Issue With its Always-Incorrect Control Flow Implementation Low
CVE-2026-35343 was published for coreutils (Rust) Apr 22, 2026
KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a... Moderate Unreviewed
CVE-2026-41527 was published Apr 22, 2026
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views Moderate
CVE-2026-6608 was published for fschat (pip) Apr 20, 2026
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache Moderate
CVE-2026-40942 was published for dev.dsf:dsf-bpe-process-api-v2 (Maven) Apr 15, 2026
Wasmtime has host panic when Winch compiler executes `table.fill` Moderate
CVE-2026-34946 was published for wasmtime (Rust) Apr 9, 2026
shumbo Credited to shumbo and alexcrichton alexcrichton alexcrichton
OpenClaw: Endpoint persists after trust decline, leaking gateway credentials Moderate
CVE-2026-41300 was published for openclaw (npm) Apr 3, 2026
zsxsoft Credited to zsxsoft and KeenSecurityLab KeenSecurityLab KeenSecurityLab
Nest Fastify HEAD Request Middleware Bypass High
CVE-2026-33011 was published for @nestjs/platform-fastify (npm) Mar 17, 2026
kamilmysliwiec Credited to kamilmysliwiec
Cosmos EVM: incorrect state handling during nested EVM execution paths Critical
GHSA-54gx-3cgr-7mfm was published for github.com/cosmos/evm (Go) Mar 11, 2026
The rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collide High
CVE-2026-26267 was published for soroban-sdk-macros (Rust) Feb 17, 2026
leighmcculloch Credited to leighmcculloch, mootz12, nan-zellic, and dmkozh mootz12 mootz12
nan-zellic nan-zellic dmkozh dmkozh
ProTip! Advisories are also available from the GraphQL API