Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
Nadav0077 Credited to Nadav0077
web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling Moderate
CVE-2026-40072 was published for web3 (pip) Apr 4, 2026
Nadav0077 Credited to Nadav0077
undici WebSocket client vulnerable to denial of service via fragment count bypass High
CVE-2026-12151 was published for undici (npm) Jun 19, 2026
lpinca Credited to lpinca, Nadav0077, and UlisesGascon Nadav0077 Nadav0077
UlisesGascon UlisesGascon
Authelia Missing Username Canonicalization in Basic Auth (LDAP) Low
CVE-2026-47203 was published for github.com/authelia/authelia/v4 (Go) May 29, 2026
Nadav0077 Credited to Nadav0077, james-d-elliott, nightah, and Crowley723 james-d-elliott james-d-elliott
nightah nightah Crowley723 Crowley723
ws: Memory exhaustion DoS from tiny fragments and data chunks High
CVE-2026-48779 was published for ws (npm) Jun 15, 2026
Nadav0077 Credited to Nadav0077
MCP Python SDK: WebSocket server transport does not support Host/Origin validation High
CVE-2026-59950 was published for mcp (pip) Jul 16, 2026
nitish-yaddala Credited to nitish-yaddala, Nadav0077, dodge1218, gistrec, and u-ktdi Nadav0077 Nadav0077
dodge1218 dodge1218 gistrec gistrec u-ktdi u-ktdi
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role High
CVE-2026-53515 was published for @better-auth/sso (npm) Jul 20, 2026
Nadav0077 Credited to Nadav0077
find-my-way: DDoS with HTTP2 High
CVE-2026-47219 was published for find-my-way (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077 and mcollina mcollina mcollina
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
CVE-2026-73419 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
Nadav0077 Credited to Nadav0077 and igorpyan igorpyan igorpyan
ProTip! Advisories are also available from the GraphQL API