-
Notifications
You must be signed in to change notification settings - Fork 699
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-x732-6j76-qmhm] Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
#8945
opened Aug 2, 2026 by
FROWNINGdev
Loading…
[GHSA-4vcf-q4xf-f48m] Better Auth Passkey plugin allows deletion of arbitrary passkeys by ID
#8944
opened Aug 2, 2026 by
FROWNINGdev
Loading…
[GHSA-569q-mpph-wgww] Better Auth affected by external request basePath modification DoS
#8943
opened Aug 2, 2026 by
FROWNINGdev
Loading…
[GHSA-9m9p-7p6h-xv99] FileGator accepts arbitrary Unix permission values via...
#8940
opened Aug 2, 2026 by
moizxsec
Loading…
[GHSA-qcxq-75wr-5cm8] ldap3_proto has LDAP Filter stack exhaustion
#8939
opened Aug 2, 2026 by
micolous
Loading…
[GHSA-r5fr-9gmv-jggh] scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
#8938
opened Aug 2, 2026 by
micolous
Loading…
[GHSA-hhpq-7wg4-36jm] CakePHP Authentication: Open redirect weakness via backslash bypass
#8937
opened Aug 2, 2026 by
aquaturtlium
Loading…
GHSA-qwww-vcr4-c8h2: split affected range — fix backported to react-router 7.18.2
#8936
opened Aug 2, 2026 by
BenjaminLimb
Loading…
[GHSA-jfv9-68m5-gjjr] mem0 server lacks authentication and authorization controls for its memory management API endpoints
#8930
opened Aug 1, 2026 by
donny-devops
Loading…
[GHSA-q9r5-6hrr-9ph7] Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
#8929
opened Aug 1, 2026 by
donny-devops
Loading…
[GHSA-r9vw-cjf9-xh4x] ProcessWire Cross Site Request Forgery vulnerability
#8928
opened Jul 31, 2026 by
ryancramerdesign
Loading…
[GHSA-j965-2qgj-vjmq] JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3
#8926
opened Jul 31, 2026 by
dloetzke
Loading…
[GHSA-frvp-7c67-39w9] Node.js Adapter for Hono: Path traversal in
serve-static on Windows via encoded backslash (%5C)
#8919
opened Jul 31, 2026 by
yusukebe
Loading…
[GHSA-w4f7-4cxr-rv3c] cowboy and gun affected by an HTTP Request/Response Splitting vulnerability
#8906
opened Jul 31, 2026 by
StrongOliverV
Loading…
[GHSA-c3fc-8qff-9hwx] Bouncy Castle has an LDAP injection
#8902
opened Jul 30, 2026 by
sislampanw
Loading…
Update GHSA-rjr7-jggh-pgcp.json due to incorrect middleware in path
#8900
opened Jul 30, 2026 by
pjroth
Loading…
[GHSA-jx74-cqjv-2c67] Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
#8899
opened Jul 30, 2026 by
BarakSrour
Loading…
[GHSA-86vw-mfpg-wwv9] jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
#8897
opened Jul 30, 2026 by
mattbaileyuk
Loading…
[GHSA-p5rm-jg5c-8c77] Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
#8894
opened Jul 30, 2026 by
BarakSrour
Loading…
[GHSA-659w-93r5-9j6m] Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
#8892
opened Jul 30, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-cx4m-2p55-rw7j] Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
#8891
opened Jul 30, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-4v8g-86x5-3vrc] Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
#8890
opened Jul 30, 2026 by
maheshwarivijaykumar
Loading…
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.