-
Notifications
You must be signed in to change notification settings - Fork 774
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-gqch-g4w5-7qcw] MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
#9652
opened Sep 20, 2026 by
Fanxy13
Loading…
[GHSA-2v4p-qf9q-27wj] gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing
:authority and Host headers
#9651
opened Sep 20, 2026 by
karelvanhecke
Loading…
[GHSA-8p3j-58qw-jhp4] Add finder credit and Ubuntu USN reference (CVE-2022-0530)
#9650
opened Sep 20, 2026 by
ByteHackr
Loading…
[GHSA-66cv-5wq4-p78m] Add finder credit and affected package range (CVE-2026-81829)
#9648
opened Sep 20, 2026 by
ByteHackr
Loading…
[GHSA-wj94-fvj2-f29x] Add finder credit and Ubuntu USN reference (CVE-2022-0529)
#9649
opened Sep 20, 2026 by
ByteHackr
Loading…
[GHSA-pghw-ch4m-h3f9] Add finder credit and fix reference (CVE-2026-78367)
#9647
opened Sep 20, 2026 by
ByteHackr
Loading…
[GHSA-c9ff-59g8-m36q] Add finder credit and affected Maven ranges (CVE-2026-84218)
#9645
opened Sep 20, 2026 by
ByteHackr
Loading…
[GHSA-jhqm-m4j3-wqq2] Add finder credit (CVE-2026-79655)
#9646
opened Sep 20, 2026 by
ByteHackr
Loading…
[GHSA-r79c-pqj3-577x] Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
#9644
opened Sep 20, 2026 by
identity-wael
Loading…
[GHSA-9m44-rr2w-ppp7] Swift Crypto: X-Wing HPKE Decapsulation Accepts Malformed Ciphertext Length
#9643
opened Sep 20, 2026 by
identity-wael
Loading…
[GHSA-q3g2-m552-3r9c] swift-nio-http2: Missing CR/LF/NUL validation in header values
#9642
opened Sep 20, 2026 by
identity-wael
Loading…
[GHSA-4xqx-pqpj-9fqw] gajira-create GitHub action vulnerable to arbitrary code execution
#9641
opened Sep 20, 2026 by
sharadverma638
Loading…
[GHSA-jgm3-qmp2-c4p7] Vendure: Unauthenticated ReDoS via
regex filter on SQLite backends
#9640
opened Sep 20, 2026 by
checkmator
Loading…
[GHSA-q97c-8qh3-fpc6] phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
#9639
opened Sep 20, 2026 by
hexblot
Loading…
[GHSA-5h8j-6crg-7rmw] LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
#9638
opened Sep 19, 2026 by
checkmator
Loading…
[GHSA-fxg7-897c-57mp] Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
#9637
opened Sep 19, 2026 by
checkmator
Loading…
[GHSA-xq8m-7c5p-c2r6] Auth0 Next.js SDK has Improper Proxy Cache Lookup
#9636
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-5vv4-hvf7-2h46] Command Injection via Unsanitized
locate Output in versions() — systeminformation
#9635
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-c83g-rgw3-j3cx] Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
#9633
opened Sep 19, 2026 by
leaan88
Loading…
[GHSA-8wpr-639p-ccrj] Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
#9632
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-xc6g-ggrc-qq4r] Cross-Site Scripting in sanitize-html
#9631
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-p2x3-8689-cwpg] Parse Server's GraphQL WebSocket endpoint bypasses security middleware
#9630
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-25hc-qcg6-38wj] socket.io has an unhandled 'error' event
#9629
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-984m-rj28-8c6x] Plone unauthorized member addition vulnerability
#9627
opened Sep 19, 2026 by
nikpivkin
Loading…
[GHSA-22jr-vc7j-g762] Potential buffer overflow in psd-tools
#9626
opened Sep 19, 2026 by
nikpivkin
Loading…
Previous Next
ProTip!
Mix and match filters to narrow down what you’re looking for.