Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

343 advisories

Loading
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials High
GHSA-3f6p-5ww8-9rcr was published for mysql2 (npm) Sep 1, 2026
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55857 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB has cleartext password disclosure to a MITM on the initial-handshake Moderate
CVE-2026-55856 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55854 was published for mariadb (npm) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` High
CVE-2026-55215 was published for mariadb (npm) Aug 28, 2026
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) Critical
GHSA-93qj-5q5v-3c2h was published for pantheon-agents (pip) Aug 26, 2026
gasbugs Credited to gasbugs
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect Moderate
GHSA-h4mf-4v27-hggj was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys Moderate
GHSA-8mxv-9xhp-86h4 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering Moderate
CVE-2026-71293 was published for statamic/cms (Composer) Aug 5, 2026
Wings exposes node configuration secrets through egg configuration-file templating Critical
CVE-2026-52855 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
robertdrakedennis Credited to robertdrakedennis
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url High
CVE-2026-67425 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted High
CVE-2026-67427 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry Critical
CVE-2026-59891 was published for @sigstore/oci (npm) Jul 21, 2026
gyubin02 Credited to gyubin02
File Browser: Share API exposes the password hash and bypass token Low
CVE-2026-62684 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
CVE-2026-67339 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
nebula-mesh: Operator session tokens stored in plaintext in the database High
CVE-2026-53603 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
Excon does not redact additional sensitive/risky headers when following redirects Moderate
CVE-2026-54171 was published for excon (RubyGems) Jul 10, 2026
SnailSploit Credited to SnailSploit, Lokeninfinitypoint, and Amayyas Lokeninfinitypoint Lokeninfinitypoint
Amayyas Amayyas
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps High
CVE-2026-55431 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
LaunchServer FileServerHandler has an unauthenticated path traversal issue Critical
CVE-2026-54617 was published for pro.gravit.launcher:launchserver-api (Maven) Jul 2, 2026
getclaude Credited to getclaude
ProTip! Advisories are also available from the GraphQL API