Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

611 advisories

Loading
LiteLLM: Authentication Bypass via Host Header Injection Critical
CVE-2026-49468 was published for litellm (pip) Jun 16, 2026
LilThawg29 Credited to LilThawg29
Duplicate Advisory: Zalo allowFrom could bind to mutable display names High
GHSA-w7m7-3xcf-mp48 was published for openclaw (npm) Jun 16, 2026 withdrawn
Duplicate Advisory: Discord allowFrom could bind to mutable display names High
GHSA-p44v-rx83-vjp4 was published for openclaw (npm) Jun 16, 2026 withdrawn
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` High
CVE-2026-52845 was published for github.com/caddyserver/caddy (Go) Jun 16, 2026
Vincent550102 Credited to Vincent550102 and dunglas dunglas dunglas
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes Moderate
CVE-2026-54308 was published for n8n (npm) Jun 16, 2026
nkoorty Credited to nkoorty and jjjutla jjjutla jjjutla
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions. Moderate Unreviewed
CVE-2026-42662 was published Jun 15, 2026
Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions. High Unreviewed
CVE-2026-27089 was published Jun 15, 2026
purpshell Credited to purpshell and SheIITear SheIITear SheIITear
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections High
CVE-2026-47737 was published for puma (RubyGems) Jun 9, 2026
vxhex Credited to vxhex and nateberkopec nateberkopec nateberkopec
NocoDB: Cross-Workspace Integration Use in Connection Test Moderate
CVE-2026-47381 was published for nocodb (npm) Jun 5, 2026
DongyangLyu Credited to DongyangLyu
Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment Moderate
CVE-2026-48016 was published for shopware/core (Composer) Jun 4, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution Moderate
CVE-2026-45056 was published for matrix-sdk-crypto (Rust) Jun 4, 2026
Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret Moderate
CVE-2026-44476 was published for doorkeeper-openid_connect (RubyGems) Jun 4, 2026
55728 Credited to 55728
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. Critical Unreviewed
CVE-2026-8644 was published Jun 1, 2026
ProTip! Advisories are also available from the GraphQL API