Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

668 advisories

Loading
TYPO3 CMS - Broken Access Control in Backend and Install Tool High
CVE-2026-19418 was published for typo3/cms-backend (Composer) Sep 1, 2026
mcp-go accepted requests on its HTTP transports without checking the Host header.... High Unreviewed
CVE-2026-81092 was published Aug 27, 2026
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport High
CVE-2026-55637 was published for github.com/geiserx/genieacs-mcp (Go) Aug 25, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Moderate
CVE-2026-67448 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
arpitjain099 Credited to arpitjain099
ProTip! Advisories are also available from the GraphQL API