Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,329 advisories

Loading
pypdf: Possible large memory usage for large /ToUnicode streams Moderate
CVE-2026-71870 was published for pypdf (pip) Aug 7, 2026
stefan6419846 Credited to stefan6419846
pypdf: Possible long runtimes/large memory usage for large CID font width ranges Moderate
CVE-2026-71852 was published for pypdf (pip) Aug 7, 2026
7thParkk Credited to 7thParkk and stefan6419846 stefan6419846 stefan6419846
juli Credited to juli
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure Moderate
CVE-2026-71850 was published for hono (npm) Aug 7, 2026
raster0x2a Credited to raster0x2a
Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low
CVE-2026-71849 was published for hono (npm) Aug 7, 2026
morgan-coded Credited to morgan-coded
Hono: Algorithmic Complexity DoS in Language Middleware Moderate
CVE-2026-71848 was published for hono (npm) Aug 7, 2026
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors High
CVE-2026-67422 was published for pymdown-extensions (pip) Aug 7, 2026
seankohjs Credited to seankohjs
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules Critical
CVE-2026-63223 was published for codeigniter4/framework (Composer) Aug 7, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames High
CVE-2026-63222 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions Critical
CVE-2026-63221 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() Moderate
CVE-2026-63220 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
jsii-diff: Command Injection via npm: package argument High
CVE-2026-15895 was published for jsii-diff (npm) Aug 7, 2026
Dremig Credited to Dremig
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
alexandre-daubois Credited to alexandre-daubois
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header Moderate
CVE-2026-66062 was published for @sveltejs/kit (npm) Aug 7, 2026
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint Moderate
GHSA-7c4v-fwgw-9rf7 was published for nuxt (npm) Aug 7, 2026
Saku0512 Credited to Saku0512
go-git: Malicious reference names may modify files outside the reference storage Moderate
CVE-2026-71557 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
Saku0512 Credited to Saku0512
go-git: Worktree operations may follow symlinks High
CVE-2026-71556 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
kodareef5 Credited to kodareef5 and HughLewis20 HughLewis20 HughLewis20
manus-use Credited to manus-use
manus-use Credited to manus-use
tinyb0y Credited to tinyb0y
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
ProTip! Advisories are also available from the GraphQL API