Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36 advisories

Loading
manus-use Credited to manus-use
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS) High
CVE-2026-81516 was published for Steeltoe.Discovery.Consul (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS) High
CVE-2026-81515 was published for Steeltoe.Discovery.Eureka (NuGet) Sep 17, 2026
manus-use Credited to manus-use
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets Moderate
CVE-2026-75523 was published for Steeltoe.Management.Endpoint (NuGet) Sep 17, 2026
manus-use Credited to manus-use
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing Moderate
CVE-2026-85732 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
manus-use Credited to manus-use
manus-use Credited to manus-use and ncw ncw ncw
manus-use Credited to manus-use and Classic298 Classic298 Classic298
manus-use Credited to manus-use
manus-use Credited to manus-use
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Critical
CVE-2026-55559 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
MarkLee131 Credited to MarkLee131 and manus-use manus-use manus-use
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` Critical
CVE-2026-55511 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
Yanchon918s Credited to Yanchon918s and manus-use manus-use manus-use
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
manus-use Credited to manus-use
manus-use Credited to manus-use
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing High
GHSA-jwjp-4649-v8jp was published for SIPSorcery (NuGet) Aug 12, 2026
manus-use Credited to manus-use
manus-use Credited to manus-use
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction Moderate
CVE-2026-64663 was published for statamic/cms (Composer) Aug 6, 2026
manus-use Credited to manus-use
manus-use Credited to manus-use and Classic298 Classic298 Classic298
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count Moderate
GHSA-p538-c434-8v24 was published for GitPython (pip) Aug 3, 2026
manus-use Credited to manus-use
manus-use Credited to manus-use
ProTip! Advisories are also available from the GraphQL API