Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,956 advisories

Loading
Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks Moderate
CVE-2026-11986 was published for org.keycloak:keycloak-rest-admin-ui-ext (Maven) Jun 11, 2026
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates High
CVE-2024-45747 was published for org.geoserver.web:gs-web-app (Maven) Aug 19, 2026
mbadanoiu Credited to mbadanoiu and sikeoka sikeoka sikeoka
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing High
CVE-2026-53966 was published for org.xwiki.platform:xwiki-platform-livedata-livetable (Maven) Aug 19, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting Moderate
GHSA-5wjw-h8x5-v65m was published for org.jboss.hal:hal-console (Maven) Jan 14, 2025 withdrawn
Keycloak has a Time-of-check Time-of-use (TOCTOU) Race Condition Moderate
CVE-2026-9796 was published for org.keycloak:keycloak-server (Maven) May 28, 2026
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML Moderate
CVE-2026-40986 was published for org.springframework.webflow:spring-webflow (Maven) Jun 11, 2026
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification Moderate
CVE-2026-40992 was published for org.springframework.boot:spring-boot-starter-mail (Maven) Jun 11, 2026
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser Moderate
CVE-2026-40985 was published for org.springframework.webflow:spring-webflow (Maven) Jun 11, 2026
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max Low
CVE-2026-61634 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
Alexender676 Credited to Alexender676
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM Moderate
CVE-2026-63336 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
RabbitMQ Java client malformed body frame triggers raw command assembler exception Moderate
CVE-2026-63335 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
hibrian827 Credited to hibrian827
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading High
CVE-2026-63337 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation High
CVE-2026-69219 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS High
CVE-2026-69220 was published for com.rabbitmq:amqp-client (Maven) Aug 18, 2026
lucianjohnhouse Credited to lucianjohnhouse
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection High
CVE-2026-55839 was published for io.kestra:kestra (Maven) Aug 18, 2026
5h1kh4r Credited to 5h1kh4r
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS High
CVE-2026-53659 was published for org.http4k:http4k-core (Maven) Aug 17, 2026
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI Moderate
CVE-2026-54147 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI High
CVE-2026-54148 was published for org.http4k:http4k-security-digest (Maven) Aug 17, 2026
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service High
CVE-2026-53752 was published for org.docx4j:docx4j-core (Maven) Aug 17, 2026
Silverpeas mishandles the "Personal space" feature that is selected when no componentId is set Moderate
CVE-2026-53698 was published for org.silverpeas.core:silverpeas-core (Maven) Jun 10, 2026
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite Moderate
CVE-2026-59903 was published for io.netty:netty-codec-http (Maven) Aug 17, 2026
violetagg Credited to violetagg
Netty: Memory Exhaustion in SctpMessageCompletionHandler High
CVE-2026-59902 was published for io.netty:netty-transport-sctp (Maven) Aug 17, 2026
violetagg Credited to violetagg
carbon-apimgt does not properly restrict uploaded files Critical
CVE-2025-13590 was published for org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.admin.v1 (Maven) Feb 19, 2026
sealbenb Credited to sealbenb
Jenkins GitHub Plugin has an XSS vulnerability Critical
CVE-2026-42523 was published for com.coravy.hudson.plugins.github:github (Maven) Apr 29, 2026
sealbenb Credited to sealbenb
ProTip! Advisories are also available from the GraphQL API