Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

20 advisories

Loading
tonghuaroot Credited to tonghuaroot and Classic298 Classic298 Classic298
tonghuaroot Credited to tonghuaroot and pboling pboling pboling
anir0y Credited to anir0y, manus-use, sermikr0, adamyordan, Pig-Tail, tonghuaroot, and alimony manus-use manus-use
sermikr0 sermikr0 adamyordan adamyordan Pig-Tail Pig-Tail tonghuaroot tonghuaroot alimony alimony
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq) High
GHSA-r7wm-3cxj-wff9 was published for com.fasterxml.jackson.core:jackson-core (Maven) Jul 21, 2026
tonghuaroot Credited to tonghuaroot, pjfanning, and cowtowncoder pjfanning pjfanning
cowtowncoder cowtowncoder
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests High
CVE-2026-58436 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware High
GHSA-mqxv-9rm6-w8qc was published for github.com/lin-snow/ech0 (Go) Jul 14, 2026
tonghuaroot Credited to tonghuaroot
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) High
CVE-2026-50553 was published for github.com/enchant97/note-mark/backend (Go) Jul 9, 2026
tonghuaroot Credited to tonghuaroot, Yunkaiwjs, and enchant97 Yunkaiwjs Yunkaiwjs
enchant97 enchant97
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests High
CVE-2026-50197 was published for github.com/zalando/skipper (Go) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier High
GHSA-mjgf-xj26-9qf9 was published for pay (RubyGems) Jul 1, 2026
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot
tonghuaroot Credited to tonghuaroot and endelwar endelwar endelwar
tonghuaroot Credited to tonghuaroot and UlisesGascon UlisesGascon UlisesGascon
tonghuaroot Credited to tonghuaroot
ProTip! Advisories are also available from the GraphQL API