Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,755 advisories

Loading
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: MCP Registry API readable without authentication Moderate
GHSA-pr6h-vr44-xq8j was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion High
GHSA-xwmw-prc4-v3cr was published for github.com/obot-platform/obot (Go) Sep 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade) Moderate
CVE-2026-71537 was published for paymenter/paymenter (Composer) Sep 18, 2026
Pig-Tail Credited to Pig-Tail and CorwinDev CorwinDev CorwinDev
io.moquette:moquette-broker has a Missing Authorization issue High
CVE-2026-85058 was published for io.moquette:moquette-broker (Maven) Sep 18, 2026
Fireees Credited to Fireees and Robin-szu Robin-szu Robin-szu
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass Critical
CVE-2026-59163 was published for mnemosyne-memory (pip) Sep 18, 2026
dplush Credited to dplush
Perses's unvalidated project parameter enables filesystem path traversal High
CVE-2026-63445 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure High
CVE-2026-63199 was published for github.com/perses/perses (Go) Sep 18, 2026
ImDuong Credited to ImDuong
Perses's project query parameter authorization bypass exposes cross-project resources High
CVE-2026-63458 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer High
CVE-2026-91127 was published for @file-viewer/doc (npm) Sep 18, 2026
shashank420 Credited to shashank420
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) High
CVE-2026-77301 was published for adm-zip (npm) Sep 18, 2026
joszamama Credited to joszamama
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools Moderate
CVE-2026-77339 was published for github.com/f1bonacc1/process-compose (Go) Sep 18, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials High
CVE-2026-81505 was published for github.com/frain-dev/convoy (Go) Sep 18, 2026
GrayOM Credited to GrayOM
md-editor-v3: XSS via fenced-code language rendering bypass Moderate
CVE-2026-84992 was published for md-editor-v3 (npm) Sep 18, 2026
koyokr Credited to koyokr
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets Moderate
CVE-2026-63406 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
Faze-up Credited to Faze-up
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing Critical
CVE-2026-63374 was published for anyio (pip) Sep 18, 2026
AnyIO process-pool workers can block indefinitely on undrained stderr Moderate
CVE-2026-64847 was published for anyio (pip) Sep 18, 2026
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body Moderate
CVE-2026-63405 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement High
CVE-2026-58197 was published for github.com/stacklok/toolhive (Go) Sep 18, 2026
xxradar Credited to xxradar, ChrisJBurns, JAORMX, jhrozek, kantord, and eleftherias ChrisJBurns ChrisJBurns
JAORMX JAORMX jhrozek jhrozek kantord kantord eleftherias eleftherias
5ud0er Credited to 5ud0er
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion High
CVE-2026-61833 was published for zotregistry.dev/zot/v2 (Go) Sep 18, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation Moderate
CVE-2026-61795 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
PhucQuan Credited to PhucQuan
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement High
CVE-2026-61672 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
5ud0er Credited to 5ud0er
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic Moderate
CVE-2026-61794 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
PhucQuan Credited to PhucQuan
ProTip! Advisories are also available from the GraphQL API