Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

573 advisories

Loading
Sulu: Fix authorization bypass when creating preview links Moderate
CVE-2026-82394 was published for sulu/sulu (Composer) Sep 2, 2026
Sulu: Media move/update authorization bypass (IDOR) Moderate
CVE-2026-82395 was published for sulu/sulu (Composer) Sep 2, 2026
smakarim Credited to smakarim
TA-MU-TA Credited to TA-MU-TA
Snipe-IT has incorrect permission for legacy license checkin API Moderate
CVE-2026-55479 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT's import created_by can be overwritten Moderate
CVE-2026-55475 was published for snipe/snipe-it (Composer) Aug 28, 2026
ashrexon Credited to ashrexon
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation Moderate
CVE-2026-55472 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has an authorization bypass on print inventory page Moderate
CVE-2026-55462 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
phpMyFAQ public FAQ APIs expose inactive FAQ content Moderate
GHSA-mf8r-wm2w-f8c5 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
YHalo-wyh Credited to YHalo-wyh
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint Moderate
GHSA-vx2m-jpxr-xv7w was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
riodrwn Credited to riodrwn
Mattermost doesn't require system-level permission when patching protected default system roles Moderate
CVE-2026-6739 was published for github.com/mattermost/mattermost-server (Go) Jun 12, 2026
Copyparty vulnerable to file/dirkey confusion Moderate
CVE-2026-70657 was published for copyparty (pip) Aug 18, 2026
poolcritter Credited to poolcritter
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users Moderate
GHSA-8rw6-p7m8-63jp was published for surrealdb (Rust) Aug 14, 2026
msanchezdev Credited to msanchezdev
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Moderate
CVE-2026-54765 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
gooood4u Credited to gooood4u
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Moderate
CVE-2026-71325 was published for github.com/traefik/traefik (Go) Aug 6, 2026
ttzero25 Credited to ttzero25
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
CVE-2026-65602 was published for github.com/traefik/traefik/v3 (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd and james-yusuke james-yusuke james-yusuke
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
GHSA-7m3p-wc52-rmc6 was published for github.com/traefik/traefik (Go) Jul 22, 2026 withdrawn
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
CVE-2026-65601 was published for Traefik (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
GHSA-6mxq-jr92-3h2r was published for github.com/traefik/traefik (Go) Jul 22, 2026 withdrawn
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup Moderate
CVE-2026-70488 was published for open-webui (pip) Aug 4, 2026
whyiug Credited to whyiug and Classic298 Classic298 Classic298
Open WebUI: Users denied the image-generation permission can still generate images via chat completions Moderate
CVE-2026-70484 was published for open-webui (pip) Aug 4, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization Moderate
CVE-2026-59889 was published for com.fasterxml.jackson.core:jackson-databind (Maven) Jul 21, 2026
CyberKareem Credited to CyberKareem and mprins mprins mprins
ProTip! Advisories are also available from the GraphQL API