Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization Moderate
CVE-2026-55766 was published for guzzlehttp/psr7 (Composer) Jun 19, 2026
iliaal Credited to iliaal
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts Moderate
CVE-2026-55767 was published for guzzlehttp/guzzle (Composer) Jun 19, 2026
iliaal Credited to iliaal and EchoTydes EchoTydes EchoTydes
Composer: Arbitrary file write outside vendor via malicious transitive package name High
CVE-2026-59948 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure) Moderate
CVE-2026-59947 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files Moderate
CVE-2026-59946 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
Grav: Unauthenticated denial of service via unbounded image derivative dimensions High
CVE-2026-53653 was published for getgrav/grav (Composer) Aug 14, 2026
iliaal Credited to iliaal
Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) Moderate
CVE-2026-61842 was published for getgrav/grav (Composer) Sep 2, 2026
iliaal Credited to iliaal
ProTip! Advisories are also available from the GraphQL API