Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

89 advisories

Loading
OpenStack Ironic allows Boot Script Injection Moderate
CVE-2026-46447 was published for ironic (pip) Jun 4, 2026
Talos Linux has a local privilege escalation from untrusted workloads High
GHSA-m38g-vww2-mvgx was published for github.com/siderolabs/talos (Go) May 7, 2026
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres High
CVE-2026-42997 was published for ironic-python-agent (pip) May 5, 2026
Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message Moderate
CVE-2026-35543 was published for roundcube/roundcubemail (Composer) Apr 3, 2026
Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message Moderate
CVE-2026-35545 was published for roundcube/roundcubemail (Composer) Apr 3, 2026
Roundcube: Bypass of remote image blocking via crafted BODY background attribute Moderate
CVE-2026-35542 was published for roundcube/roundcubemail (Composer) Apr 3, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages Moderate
CVE-2026-35544 was published for roundcube/roundcubemail (Composer) Apr 3, 2026
Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages Moderate
CVE-2026-35540 was published for roundcube/roundcubemail (Composer) Apr 3, 2026
ProTip! Advisories are also available from the GraphQL API