GitHub Security Advisories
Open-source package ecosystem coverage across npm / PyPI / Maven / Go / RubyGems and more.
52,210 advisories tracked · showing 100
- Oct 6, 2026GHSA-g3x9-2gpf-9qg7unknownCVE-2026-82988
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard...
- Oct 6, 2026GHSA-wx6m-rmf7-wpp6unknownCVE-2026-82989
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows...
- Oct 6, 2026GHSA-c6m2-r96x-hp8cMediumCVSS 7.3CVE-2026-105471
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to...
- Oct 6, 2026GHSA-chp6-57pf-j5gjMediumCVSS 7.3CVE-2026-105469
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to...
- Oct 6, 2026GHSA-gr66-x5pq-8g2gCriticalCVE-2026-21589
h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira...
- Oct 6, 2026GHSA-8wvp-xv32-wv33MediumCVSS 7.3CVE-2026-105470
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to...
- Oct 6, 2026GHSA-r588-8qfc-26mvCriticalCVE-2026-91107
openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an...
- Oct 6, 2026GHSA-7rx7-qv2r-vcjfMediumCVSS 7.3CVE-2026-105468
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to...
- Oct 6, 2026GHSA-pwxc-m348-gxg8LowCVSS 4.3CVE-2026-103546
In MongoDB Controllers for Kubernetes, insufficient validation of Ops Manager backup...
- Oct 6, 2026GHSA-f4ch-vxwc-3p2mMediumCVSS 4.3CVE-2026-105747
Docling simplifies document processing by parsing diverse formats and providing integrations with...
- Oct 6, 2026GHSA-w4wm-q9h6-q3vfMediumCVE-2026-0482
In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot mode—when enabled...
- Oct 6, 2026GHSA-2xg6-gqcc-77jwHighCVE-2026-0461
Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+...
- Oct 6, 2026GHSA-q43m-vhcp-mhvmMediumCVSS 5.9CVE-2026-105750
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
- Oct 6, 2026GHSA-ph3r-5jfg-f84fMediumCVSS 6.5CVE-2026-105753
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later request reusing the same media hash trips a receiver assertion in the engine core
- Oct 6, 2026GHSA-935w-9g4m-p28pLowCVSS 3.1CVE-2026-105752
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant prefix-cache membership oracle
- Oct 5, 2026GHSA-g6x2-hccm-hh4mMediumCVE-2026-102598
Werkzeug safe_join() allows Windows special device names
- Oct 5, 2026GHSA-v5rq-49vh-5v5cCriticalCVE-2026-102829
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
- Oct 5, 2026GHSA-x6jw-m9v5-85vhCriticalCVE-2026-102828
simple-git unsafe-operation guard does not block trailer command configuration
- Oct 5, 2026GHSA-g4wm-2vf7-vfgrHighCVSS 8.1CVE-2026-102826
simple-git allows command execution through unblocked Git configuration includes
- Oct 5, 2026GHSA-858h-whjf-mvg5HighCVSS 8.1CVE-2026-102827
simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
- Oct 5, 2026GHSA-v4x9-3549-crwvHighCVSS 8.4CVE-2026-96749
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding
- Oct 5, 2026GHSA-vp6j-j7w5-5xjjHighCVSS 6.5CVE-2026-96748
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters
- Oct 5, 2026GHSA-qx36-8mw2-4r3xMediumCVSS 5.0CVE-2026-96747
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption
- Oct 5, 2026GHSA-wfpm-5gcm-94cgHighCVSS 7.5CVE-2026-102600
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
- Oct 5, 2026GHSA-7m6h-rg42-m449MediumCVSS 5.4CVE-2026-104181
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
- Oct 5, 2026GHSA-x33g-cr3x-6449MediumCVSS 6.5CVE-2026-102275
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
- Oct 5, 2026GHSA-6688-9rhm-gjv2LowDisclosed before NVD
DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
- Oct 5, 2026GHSA-x6mc-67gf-chw4MediumCVSS 5.3CVE-2026-105758
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_frames, which the num_frames ceiling does not reach
- Oct 5, 2026GHSA-58v5-2m8f-94prMediumCVSS 5.3CVE-2026-105760
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
- Oct 5, 2026GHSA-ph72-cqr5-qpp7MediumCVSS 6.5CVE-2026-105754
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied features
- Oct 5, 2026GHSA-85xf-c7hm-whqwMediumCVSS 6.5CVE-2026-105757
vLLM: Structured-output request errors escape the request boundary and terminate the shared EngineCore — engine-fatal denial of service (3 sites)
- Oct 5, 2026GHSA-2phq-3phc-84pxMediumCVSS 4.2CVE-2026-105755
vLLM: Flash late-interaction scoring caches query embeddings under a caller-controlled request id — cross-request integrity break and induced errors on `/score` and `/rerank`
- Oct 5, 2026GHSA-2823-qmq8-rwvjMediumCVSS 6.5CVE-2026-105756
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service
- Oct 5, 2026GHSA-2cv4-cqwr-gwf7MediumCVE-2026-104843
uv: Path traversal on Windows through wheel extraction
- Oct 5, 2026GHSA-5639-2j2p-m4mxMediumCVSS 6.5CVE-2026-102991
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
- Oct 5, 2026GHSA-r4xh-jqrq-34v2MediumCVSS 5.3Disclosed before NVD
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
- Oct 5, 2026GHSA-238p-pmpm-9mq7LowCVE-2026-103923
KaTeX: Existing prototype pollution can bypass trust restrictions
- Oct 5, 2026GHSA-54p9-h82j-f925MediumCVSS 5.3CVE-2026-104874
Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction
- Oct 5, 2026GHSA-p6vx-979v-rg4cCriticalCVSS 9.8CVE-2026-104846
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
- Oct 5, 2026GHSA-jp82-f5mq-hwhpHighCVSS 7.5CVE-2026-104845
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
- Oct 5, 2026GHSA-jqcg-44mw-7w3hCriticalCVSS 9.1CVE-2026-90711
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
- Oct 5, 2026GHSA-2mjx-qc3c-rqvcMediumCVSS 5.3Disclosed before NVD
Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
- Oct 5, 2026GHSA-6vc5-vf29-ffr2HighCVE-2026-104859
@nx/docker: OS command injection in the @nx/docker release pipeline
- Oct 5, 2026GHSA-w2vw-w76x-qr89HighDisclosed before NVD
Nx: OS command injection via git revisions and remote refs
- Oct 5, 2026GHSA-w3vv-58gj-gw77HighCVE-2026-104854
Nx daemon and plugin worker sockets are accessible to other local users
- Oct 5, 2026GHSA-hrvq-x7jp-36xvMediumCVE-2026-104853
Nx: Path traversal in nx migrate package-migrations extraction
- Oct 5, 2026GHSA-vc2v-76pw-4v95HighCVSS 7.5CVE-2026-87776
compression vulnerable to Denial of Service via memory leak on premature response close
- Oct 5, 2026GHSA-g7fw-3gjp-g5hfMediumCVSS 6.5Disclosed before NVD
OpenClaw: Channel read actions could skip target allowlists
- Oct 5, 2026GHSA-8fvv-fgr5-f8chMediumCVE-2026-88029
pymongo: PYTHON-5994 Use exact match for file ID in GridFS delete methods
- Oct 5, 2026GHSA-8fxw-fmj8-xp7jMediumCVE-2026-88023
MongoDB: GridFS data disclosure and deletion via query-operator injection in file IDs
- Oct 5, 2026GHSA-5h3f-q97h-ccvcCriticalCVSS 10.0CVE-2026-100721
vm2: NodeVM custom resolution bypasses external path boundaries
- Oct 5, 2026GHSA-2v2p-6j97-cjg9HighCVSS 8.6CVE-2026-100722
vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process
- Oct 5, 2026GHSA-489w-w794-jq94MediumCVSS 10.0CVE-2026-100723
vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
- Oct 5, 2026GHSA-6fw5-9hq8-w87gHighCVSS 7.4CVE-2026-103921
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
- Oct 5, 2026GHSA-7mx3-vvmw-hjmvHighCVE-2026-104852
GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`
- Oct 5, 2026GHSA-qqj6-54q6-cxv6MediumCVSS 6.5CVE-2026-86597
Snowflake drivers writes sensitive information to logs
- Oct 5, 2026GHSA-6f2x-v7q7-m7m5MediumDisclosed before NVD
hickory-resolver follows irrelevant CNAME records
- Oct 5, 2026GHSA-6w6g-hm98-mhgmHighDisclosed before NVD
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
- Oct 5, 2026GHSA-5j98-2g5x-46v6HighCVSS 7.5Disclosed before NVD
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
- Oct 5, 2026GHSA-rj75-hqrm-r3gfMediumCVSS 5.9CVE-2026-104844
PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion
- Oct 5, 2026GHSA-7g7c-h8rr-7p6qMediumCVE-2026-104871
Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
- Oct 5, 2026GHSA-27vj-qcqg-25rcHighCVSS 8.8CVE-2026-104851
fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote Code Execution
- Oct 5, 2026GHSA-rvm3-566m-v7fvCriticalCVSS 9.3CVE-2026-103922
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
- Oct 5, 2026GHSA-qqmp-wf37-98f9MediumCVSS 5.8CVE-2026-104872
Multiple @opentelemetry/instrumentation-* packages expose database username via unconditional db.user span attribute
- Oct 5, 2026GHSA-jggr-w7fw-pc2jMediumDisclosed before NVD
fast-copy: Stack exhaustion in fast-copy when copying deeply-nested values
- Oct 5, 2026GHSA-g2v6-rqmx-r4w6HighCVSS 7.2Disclosed before NVD
@vue/server-renderer: XSS via missing CR in attribute-name blacklist
- Oct 5, 2026GHSA-5gmw-xhrv-c9v3CriticalCVE-2026-104848
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
- Oct 5, 2026GHSA-85c8-ppgw-ccprCriticalCVE-2026-104849
Tinypool: Prototype Pollution Gadget to RCE in run() options
- Oct 5, 2026GHSA-v853-p72q-4cfwHighCVSS 7.5Disclosed before NVD
Quart leaks raw request body (incl. plaintext passwords) to stdout via stray debug print in Body.__await__
- Oct 5, 2026GHSA-fvww-7h3r-vfhpHighCVE-2026-104873
LangGraph SDK custom auth silently ignores actions= on resource decorators
- Oct 5, 2026GHSA-hqr4-qq8f-hg3xMediumCVSS 6.2CVE-2026-104182
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
- Oct 5, 2026GHSA-mjw6-4jj6-33hcMediumCVSS 5.1CVE-2026-104183
stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects
- Oct 5, 2026GHSA-f8gf-w286-fmq2HighCVSS 7.1CVE-2026-92959
vm2: `allowAsync: false` can be bypassed through Promise thenable assimilation in VM and NodeVM
- Oct 5, 2026GHSA-88hf-g992-jg85CriticalCVSS 10.0CVE-2026-92955
vm2: Sandbox Escape (NodeVM)
- Oct 5, 2026GHSA-gjq8-xm47-88rcCriticalCVSS 8.6CVE-2026-92954
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
- Oct 5, 2026GHSA-3vgf-8m4q-q4qrCriticalCVSS 10.0CVE-2026-92953
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
- Oct 5, 2026GHSA-x965-fc75-jpqhCriticalCVSS 9.0CVE-2026-92934
vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
- Oct 5, 2026GHSA-r273-hxvj-fxhpMediumCVSS 5.8CVE-2026-92933
vm2: util.getCallSites() bypasses GHSA-v27g-jcqj-v8rw host-frame redaction, leaks host call stack
- Oct 5, 2026GHSA-c8x8-7fp4-3x9wHighCVE-2026-104847
ProseMirror has a XSS vulnerability in prosemirror-view's paste handling
- Oct 5, 2026GHSA-x6m4-chr9-cg97MediumCVSS 5.8CVE-2026-92936
vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting
- Oct 5, 2026GHSA-r4fx-v8hh-22mvHighCVSS 7.5CVE-2026-92942
vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)
- Oct 5, 2026GHSA-j3hm-6rg5-mchvCriticalCVSS 10.0CVE-2026-92946
vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
- Oct 5, 2026GHSA-fcqc-726x-5wfcCriticalCVSS 10.0CVE-2026-92947
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool
- Oct 5, 2026GHSA-wjwh-qqvp-g4p4CriticalCVSS 10.0CVE-2026-92956
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
- Oct 5, 2026GHSA-4xhp-xg4w-8ppmMediumCVE-2026-105751
Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocument backend
- Oct 5, 2026GHSA-gxm5-99cw-xjw9MediumCVSS 5.8CVE-2026-74866
@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name
- Oct 5, 2026GHSA-jxw3-mjmx-3pqmCriticalCVSS 9.1CVE-2026-9205
Langflow: Weak Fernet Key via random.seed()
- Oct 5, 2026GHSA-cf6m-vc3m-7cgmCriticalCVSS 9.8CVE-2026-8505
Langflow: Unauthenticated Flow Execution via Webhook Authentication Bypass
- Oct 5, 2026GHSA-w584-2h2r-2hvfHighCVSS 8.8CVE-2026-51886
Langflow: Title Authenticated Remote Code Execution in validate_code via Malicious Decorators Description
- Oct 5, 2026GHSA-9fpm-3445-2vx4HighCVSS 8.8CVE-2026-7700
Langflow: Prompt injection in Langflow Smart Transform can lead to code execution
- Oct 5, 2026GHSA-mx4r-g275-wg5rCriticalCVSS 8.1CVE-2026-77226
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web...
- Oct 5, 2026GHSA-3q48-ggxq-27r2HighCVSS 7.0CVE-2026-105773
Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability...
- Oct 5, 2026GHSA-wr22-68gv-32xwMediumCVSS 5.5CVE-2026-105447
A flaw was found in Quay. When handling build trigger requests, the application incorrectly...
- Oct 5, 2026GHSA-g6h8-8gm7-qw94MediumCVE-2026-84900
Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security...
- Oct 5, 2026GHSA-cfhv-267f-j755LowCVSS 3.1CVE-2026-105766
Use of the backend-facing $scheme variable in the trailing-slash directory redirect in nginx.conf...
- Oct 5, 2026GHSA-99qh-3h9r-vq6xMediumCVSS 5.4CVE-2026-71297
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a...
- Oct 5, 2026GHSA-j47g-wqf7-q7w8unknownCVE-2026-78860
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of...
- Oct 5, 2026GHSA-hggc-x5gr-37phunknownCVE-2026-95265
Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor...
- Oct 5, 2026GHSA-qqh8-9c7w-5wf7unknownCVE-2026-78862
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART...
- Oct 5, 2026GHSA-4jgr-x73g-p576unknownCVE-2026-78861
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded...