Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,744 advisories

Loading
prnjlksingh Credited to prnjlksingh
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header Moderate
GHSA-9q47-3cm2-2rp8 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
arpitjain099 Credited to arpitjain099
pyLoad: Api.set_user_permission never invalidates the target's session High
GHSA-889w-m37p-88m5 was published for pyload-ng (pip) Oct 9, 2026
FlowOverFail Credited to FlowOverFail
manus-pi Credited to manus-pi and manus-use manus-use manus-use
skeletonsec Credited to skeletonsec
novice-22 Credited to novice-22
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass) High
CVE-2026-107808 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
Voilater Credited to Voilater
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs High
CVE-2026-107809 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
1491342590 Credited to 1491342590
0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser High
CVE-2026-107811 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
PLpaPLpa Credited to PLpaPLpa
Nginx UI: Node Secret Credential Exposure via URL Query Parameter High
CVE-2026-107807 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
captain99hook Credited to captain99hook
Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied High
CVE-2026-107810 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
Vincent550102 Credited to Vincent550102
pyLoad has an authentication bypass in API key validation (check_apikey cache) High
GHSA-r44w-v6gf-x3p6 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL High
CVE-2026-55797 was published for github.com/argoproj/argo-cd/v2 (Go) Oct 9, 2026
kamil-sawicki Credited to kamil-sawicki, yuvalelarat, cherez0ff, McCaulay, ria-labs-security, parameter-ai-security, and zwindler yuvalelarat yuvalelarat
cherez0ff cherez0ff McCaulay McCaulay ria-labs-security ria-labs-security parameter-ai-security parameter-ai-security zwindler zwindler
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination Moderate
CVE-2026-48484 was published for pyload-ng (pip) Oct 9, 2026
pevinkumar10 Credited to pevinkumar10
Strawberry legacy graphql-ws retains naturally completed subscription slots Low
CVE-2026-107727 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy High
CVE-2026-107728 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco and patrick91 patrick91 patrick91
fast-jwt: Verifier cache accepts expired JWTs without iat. Moderate
CVE-2026-107719 was published for fast-jwt (npm) Oct 8, 2026
SomnathDas Credited to SomnathDas, euriconicacio, BlueN0r, and kagebunsher euriconicacio euriconicacio
BlueN0r BlueN0r kagebunsher kagebunsher
Hazelcast allows arbitrary member memory access by low-privileged client Critical
CVE-2026-107726 was published for com.hazelcast:hazelcast (Maven) Oct 8, 2026
k-jamroz Credited to k-jamroz
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry Moderate
CVE-2026-107716 was published for banks (pip) Oct 8, 2026
jankesec Credited to jankesec
Banks: User-controlled prompt input can be parsed as privileged chat messages Moderate
CVE-2026-107717 was published for banks (pip) Oct 8, 2026
swordmein Credited to swordmein
Indico: Incomplete Server-Side Request Forgery (SSRF) check Moderate
CVE-2026-107394 was published for indico (pip) Oct 8, 2026
Fushuling Credited to Fushuling and RacerZ-fighting RacerZ-fighting RacerZ-fighting
Indico: Missing access check in legacy session export API Moderate
CVE-2026-107395 was published for indico (pip) Oct 8, 2026
arpitjain099 Credited to arpitjain099
ProTip! Advisories are also available from the GraphQL API