Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,538 advisories

Loading
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
miauzxw Credited to miauzxw and geo-chen geo-chen geo-chen
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover Critical
CVE-2026-59151 was published for prowler-cloud (pip) Sep 11, 2026
EQSTLab Credited to EQSTLab, AdriiiPRodri, jfagoagas, and josema-xyz AdriiiPRodri AdriiiPRodri
jfagoagas jfagoagas josema-xyz josema-xyz
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider Moderate
CVE-2026-56665 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, IAM-marco, livio-a, and Punisher100 IAM-marco IAM-marco
livio-a livio-a Punisher100 Punisher100
Shopper: Missing authorization on product removal actions in CollectionProducts component High
CVE-2026-56825 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph) Moderate
CVE-2026-56830 was published for shopper/framework (Composer) Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component High
CVE-2026-56829 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: privilege escalation via improper Livewire admin component authorization High
CVE-2026-56828 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopping privilege escalation through missing authorization in Settings components Moderate
CVE-2026-56826 was published for shopper/framework (Composer) Sep 11, 2026
baradika Credited to baradika
Shopper: Negative discount values accepted and propagated through order calculation pipeline Moderate
CVE-2026-56831 was published for shopper/framework (Composer) Sep 11, 2026
Fr6ey Credited to Fr6ey
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror) High
CVE-2026-11745 was published for com.linecorp.centraldogma:centraldogma-server-mirror-git (Maven) Sep 11, 2026
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover Critical
CVE-2026-11746 was published for com.linecorp.centraldogma:centraldogma-server (Maven) Sep 11, 2026
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion Moderate
CVE-2026-11748 was published for com.linecorp.centraldogma:centraldogma-server-auth-shiro (Maven) Sep 11, 2026
designcomputer Credited to designcomputer
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange Moderate
CVE-2026-88006 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization High
CVE-2026-88008 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ihopenre-eng Credited to ihopenre-eng
Traefik entrypoint header-name sanitization bypassed via request trailers High
CVE-2026-88004 was published for github.com/traefik/traefik/v3 (Go) Sep 10, 2026
bipol4r Credited to bipol4r
Traefik HTTP/3 Backend NTLM Connection Reuse Critical
CVE-2026-88007 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
OneZ3r0 Credited to OneZ3r0
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace Moderate
CVE-2026-88014 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
ProTip! Advisories are also available from the GraphQL API