Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,192 advisories

Loading
TA-MU-TA Credited to TA-MU-TA
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
black-shadow-007 Credited to black-shadow-007
Snipe-IT has incorrect permission for legacy license checkin API Moderate
CVE-2026-55479 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT's import created_by can be overwritten Moderate
CVE-2026-55475 was published for snipe/snipe-it (Composer) Aug 28, 2026
ashrexon Credited to ashrexon
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation Moderate
CVE-2026-55472 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has an authorization bypass on print inventory page Moderate
CVE-2026-55462 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
phpMyFAQ public FAQ APIs expose inactive FAQ content Moderate
GHSA-mf8r-wm2w-f8c5 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
YHalo-wyh Credited to YHalo-wyh
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint Moderate
GHSA-vx2m-jpxr-xv7w was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
riodrwn Credited to riodrwn
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
tabacitu Credited to tabacitu
Copyparty vulnerable to file/dirkey confusion Moderate
CVE-2026-70657 was published for copyparty (pip) Aug 18, 2026
poolcritter Credited to poolcritter
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
Duplicate Advisory: Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element Critical
GHSA-4hc4-qjfx-wjf3 was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
smakarim Credited to smakarim
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Moderate
CVE-2026-54765 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
gooood4u Credited to gooood4u
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Moderate
CVE-2026-71325 was published for github.com/traefik/traefik (Go) Aug 6, 2026
ttzero25 Credited to ttzero25
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
CVE-2026-65602 was published for github.com/traefik/traefik/v3 (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd and james-yusuke james-yusuke james-yusuke
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
CVE-2026-65601 was published for Traefik (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
legobattman Credited to legobattman and Classic298 Classic298 Classic298
ProTip! Advisories are also available from the GraphQL API