Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

53 advisories

Loading
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection High
CVE-2026-67445 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling High
CVE-2026-67446 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets High
CVE-2026-55523 was published for praisonaiagents (pip) Aug 25, 2026
rexpository Credited to rexpository
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Moderate
CVE-2026-67447 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
rexpository Credited to rexpository
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, PowerliftLog, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren PowerliftLog PowerliftLog zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Arena task endpoints can bypass underlying model access controls Moderate
CVE-2026-59225 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Moderate
CVE-2026-59212 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
smoke-wolf Credited to smoke-wolf, rexpository, and Classic298 rexpository rexpository
Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
ImageMagick: Policy Bypass in script operation due to missing checks Low
GHSA-vghg-5jrg-2398 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check Low
GHSA-v3j6-27vc-7pw2 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Heap-use-after-free via XMP profile could result in a crash Low
GHSA-qh5g-q395-cx4j was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219 Moderate
GHSA-56m6-8q75-f2rw was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass possible with matrix-backed operations Low
GHSA-rvhp-75f6-9jqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass in concatenate operation due to missing checks Moderate
CVE-2026-55628 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments Moderate
CVE-2026-55597 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Infinite Loop in connected-components when providing invalid arguments Moderate
CVE-2026-55595 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Stack Overflow in MVG decoder due to missing depth check. Moderate
CVE-2026-55594 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
CVE-2026-73416 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab PluginManager lock-rule enforcement bypass Moderate
GHSA-h5v5-8746-g7mm was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
ProTip! Advisories are also available from the GraphQL API