Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

61 advisories

Loading
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability High
CVE-2026-47303 was published for Microsoft.AspNetCore.Authentication.Negotiate (NuGet) Jul 21, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection High
CVE-2026-46619 was published for org.openidentityplatform.openam:openam-auth-msisdn (Maven) Jun 26, 2026
wodzen Credited to wodzen
OpenBao: LDAPi ldaputil (wrong escape func) Moderate
CVE-2026-55770 was published for github.com/openbao/openbao (Go) Jun 19, 2026
alcls01111 Credited to alcls01111
Apache Shiro: LDAP DN Injection in DefaultLdapRealm High
CVE-2026-49268 was published for org.apache.shiro:shiro-core (Maven) Jun 17, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule Moderate
CVE-2026-42568 was published for org.yamcs:yamcs-core (Maven) May 26, 2026
ex-cal1bur Credited to ex-cal1bur
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability Moderate
CVE-2026-46745 was published for apache-airflow-providers-fab (pip) May 26, 2026
Apache CXF has an LDAP injection vulnerability Critical
CVE-2026-44930 was published for org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (Maven) May 26, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')... Critical Unreviewed
CVE-2026-41919 was published May 19, 2026
ZITADEL has LDAP Filter Injection in Login Flow High
CVE-2026-44671 was published for github.com/zitadel/zitadel (Go) May 8, 2026
Proscan-one Credited to Proscan-one, livio-a, and wim07101993 livio-a livio-a
wim07101993 wim07101993
Lemur: LDAP Filter Injection enables post-authentication privilege escalation High
CVE-2026-44304 was published for lemur (pip) May 6, 2026
kuranikaran Credited to kuranikaran
Bouncy Castle has an LDAP injection Moderate
CVE-2026-0636 was published for org.bouncycastle:bcprov-jdk14 (Maven) Apr 17, 2026
mitmproxy has an LDAP Injection Moderate
CVE-2026-40606 was published for mitmproxy (pip) Apr 14, 2026
yueyueL Credited to yueyueL and mhils mhils mhils
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username High
CVE-2026-40193 was published for github.com/foxcpp/maddy (Go) Apr 13, 2026
RealHurrison Credited to RealHurrison and Ghost1032 Ghost1032 Ghost1032
n8n Vulnerable to LDAP Filter Injection in LDAP Node Moderate
CVE-2026-33751 was published for n8n (npm) Mar 26, 2026
allsmog Credited to allsmog
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction Moderate
CVE-2026-31828 was published for parse-server (npm) Mar 11, 2026
0xkakash1 Credited to 0xkakash1 and mtrezza mtrezza mtrezza
ProTip! Advisories are also available from the GraphQL API