-
Notifications
You must be signed in to change notification settings - Fork 698
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-qcxq-75wr-5cm8] ldap3_proto has LDAP Filter stack exhaustion
#8939
opened Aug 2, 2026 by
micolous
Loading…
[GHSA-r5fr-9gmv-jggh] scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
#8938
opened Aug 2, 2026 by
micolous
Loading…
[GHSA-hhpq-7wg4-36jm] CakePHP Authentication: Open redirect weakness via backslash bypass
#8937
opened Aug 2, 2026 by
aquaturtlium
Loading…
GHSA-qwww-vcr4-c8h2: split affected range — fix backported to react-router 7.18.2
#8936
opened Aug 2, 2026 by
BenjaminLimb
Loading…
[GHSA-jfv9-68m5-gjjr] mem0 server lacks authentication and authorization controls for its memory management API endpoints
#8930
opened Aug 1, 2026 by
donny-devops
Loading…
[GHSA-q9r5-6hrr-9ph7] Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
#8929
opened Aug 1, 2026 by
donny-devops
Loading…
[GHSA-r9vw-cjf9-xh4x] ProcessWire Cross Site Request Forgery vulnerability
#8928
opened Jul 31, 2026 by
ryancramerdesign
Loading…
[GHSA-j965-2qgj-vjmq] JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3
#8926
opened Jul 31, 2026 by
dloetzke
Loading…
[GHSA-frvp-7c67-39w9] Node.js Adapter for Hono: Path traversal in
serve-static on Windows via encoded backslash (%5C)
#8919
opened Jul 31, 2026 by
yusukebe
Loading…
[GHSA-w4f7-4cxr-rv3c] cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
#8906
opened Jul 31, 2026 by
StrongOliverV
Loading…
[GHSA-c3fc-8qff-9hwx] Bouncy Castle has an LDAP injection
#8902
opened Jul 30, 2026 by
sislampanw
Loading…
Update GHSA-rjr7-jggh-pgcp.json due to incorrect middleware in path
#8900
opened Jul 30, 2026 by
pjroth
Loading…
[GHSA-jx74-cqjv-2c67] Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
#8899
opened Jul 30, 2026 by
BarakSrour
Loading…
[GHSA-86vw-mfpg-wwv9] jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
#8897
opened Jul 30, 2026 by
mattbaileyuk
Loading…
[GHSA-p5rm-jg5c-8c77] Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
#8894
opened Jul 30, 2026 by
BarakSrour
Loading…
[GHSA-659w-93r5-9j6m] Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
#8892
opened Jul 30, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-cx4m-2p55-rw7j] Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
#8891
opened Jul 30, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-4v8g-86x5-3vrc] Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
#8890
opened Jul 30, 2026 by
maheshwarivijaykumar
Loading…
Update affected versions and CWE for GHSA-xx7c-j7h3-vjcq
#8888
opened Jul 30, 2026 by
khlaifiabilel
Loading…
[GHSA-5gvw-p9qm-jgwh] jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
#8884
opened Jul 30, 2026 by
mprins
Loading…
[GHSA-rrh3-cwwj-g5mg] Cornac before 2.6.0 contains a path traversal (Tar Slip)...
#8882
opened Jul 30, 2026 by
rahulreddykarne
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.