Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,603 advisories

Loading
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav Moderate
CVE-2026-58657 was published for getgrav/grav (Composer) Sep 16, 2026
DavidCarliez Credited to DavidCarliez
hewei-gikaku Credited to hewei-gikaku
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery High
CVE-2026-63127 was published for rmcp (Rust) Sep 16, 2026
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation Moderate
CVE-2026-61453 was published for getgrav/grav (Composer) Sep 16, 2026
alienkeric Credited to alienkeric and gemstone-source gemstone-source gemstone-source
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions Moderate
CVE-2026-57173 was published for vllm (pip) Sep 16, 2026
koonnamchok Credited to koonnamchok, DarkLight1337, and jperezdealgaba DarkLight1337 DarkLight1337
jperezdealgaba jperezdealgaba
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip() Moderate
CVE-2026-59193 was published for getgrav/grav (Composer) Sep 16, 2026
Scriptmagum Credited to Scriptmagum
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path High
CVE-2026-61599 was published for djust (pip) Sep 16, 2026
djust has broken object-level access control (IDOR) High
CVE-2026-61596 was published for djust (pip) Sep 16, 2026
djust has an authorization bypass on the WebSocket/SSE mount path Critical
CVE-2026-61594 was published for djust (pip) Sep 16, 2026
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion High
CVE-2026-68904 was published for node-opcua (npm) Sep 16, 2026
Velluso Credited to Velluso and erossignon erossignon erossignon
Chenpinji Credited to Chenpinji and bbabacan bbabacan bbabacan
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS High
CVE-2026-81192 was published for OpenTelemetry.Resources.Host (NuGet) Sep 16, 2026
martincostello Credited to martincostello and lachmatt lachmatt lachmatt
gil-maman-p Credited to gil-maman-p and hodaya-prz hodaya-prz hodaya-prz
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery Critical
CVE-2026-61559 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
ProTip! Advisories are also available from the GraphQL API