Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

25 advisories

Loading
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability High
CVE-2026-47303 was published for Microsoft.AspNetCore.Authentication.Negotiate (NuGet) Jul 21, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection High
CVE-2026-46619 was published for org.openidentityplatform.openam:openam-auth-msisdn (Maven) Jun 26, 2026
wodzen Credited to wodzen
OpenBao: LDAPi ldaputil (wrong escape func) Moderate
CVE-2026-55770 was published for github.com/openbao/openbao (Go) Jun 19, 2026
alcls01111 Credited to alcls01111
Apache Shiro: LDAP DN Injection in DefaultLdapRealm High
CVE-2026-49268 was published for org.apache.shiro:shiro-core (Maven) Jun 17, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule Moderate
CVE-2026-42568 was published for org.yamcs:yamcs-core (Maven) May 26, 2026
ex-cal1bur Credited to ex-cal1bur
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability Moderate
CVE-2026-46745 was published for apache-airflow-providers-fab (pip) May 26, 2026
Apache CXF has an LDAP injection vulnerability Critical
CVE-2026-44930 was published for org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (Maven) May 26, 2026
ZITADEL has LDAP Filter Injection in Login Flow High
CVE-2026-44671 was published for github.com/zitadel/zitadel (Go) May 8, 2026
Proscan-one Credited to Proscan-one, livio-a, and wim07101993 livio-a livio-a
wim07101993 wim07101993
Lemur: LDAP Filter Injection enables post-authentication privilege escalation High
CVE-2026-44304 was published for lemur (pip) May 6, 2026
kuranikaran Credited to kuranikaran
Bouncy Castle has an LDAP injection Moderate
CVE-2026-0636 was published for org.bouncycastle:bcprov-jdk14 (Maven) Apr 17, 2026
mitmproxy has an LDAP Injection Moderate
CVE-2026-40606 was published for mitmproxy (pip) Apr 14, 2026
yueyueL Credited to yueyueL and mhils mhils mhils
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username High
CVE-2026-40193 was published for github.com/foxcpp/maddy (Go) Apr 13, 2026
RealHurrison Credited to RealHurrison and Ghost1032 Ghost1032 Ghost1032
n8n Vulnerable to LDAP Filter Injection in LDAP Node Moderate
CVE-2026-33751 was published for n8n (npm) Mar 26, 2026
allsmog Credited to allsmog
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction Moderate
CVE-2026-31828 was published for parse-server (npm) Mar 11, 2026
0xkakash1 Credited to 0xkakash1 and mtrezza mtrezza mtrezza
Moonraker affected by LDAP search filter injection Low
CVE-2026-24130 was published for moonraker (pip) Jan 22, 2026
solovvway Credited to solovvway
pgAdmin is affected by an LDAP injection vulnerability High
CVE-2025-12764 was published for pgadmin4 (pip) Nov 13, 2025
Mattermost allows authenticated administrator to execute LDAP search filter injection Moderate
CVE-2025-4573 was published for github.com/mattermost/mattermost-server (Go) Jun 11, 2025
Apache Zeppelin: LDAP search filter query Injection Vulnerability Moderate
CVE-2024-31867 was published for org.apache.zeppelin:zeppelin-server (Maven) Apr 9, 2024
oscerd Credited to oscerd
Keycloak vulnerable to LDAP Injection on UsernameForm Login Low
CVE-2022-2232 was published for org.keycloak:keycloak-ldap-federation (Maven) Nov 29, 2023
kongold Credited to kongold
camel-ldap component allows LDAP Injection when using the filter option Critical
CVE-2022-45046 was published for org.apache.camel:camel-ldap (Maven) Dec 5, 2022
Improper Neutralization of Special Elements used in an LDAP Query in Jenkins Critical
CVE-2016-9299 was published for org.jenkins-ci.main:jenkins-core (Maven) May 14, 2022
sunSUNQ Credited to sunSUNQ
Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker High
CVE-2021-41232 was published for github.com/stevenweathers/thunderdome-planning-poker (Go) Nov 8, 2021
LDAP Injection in is-user-valid High
CVE-2021-23335 was published for is-user-valid (npm) Apr 13, 2021
LDAP Injection in ldapauth High
CVE-2015-7294 was published for ldapauth (npm) Aug 31, 2020
Moderate severity vulnerability that affects org.apache.karaf:apache-karaf Moderate
CVE-2016-8750 was published for org.apache.karaf:apache-karaf (Maven) Jan 7, 2019
ProTip! Advisories are also available from the GraphQL API