Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,932 advisories

Loading
goshs has ACL Bypass & Path Traversal Moderate
CVE-2026-66064 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
Pagy I18n locale option is not validated before being used in a file path Moderate
CVE-2026-54659 was published for pagy (RubyGems) Jul 28, 2026
7a6163 Credited to 7a6163
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source Moderate
GHSA-6xx4-9wp6-65p7 was published for skilo (Rust) Jul 28, 2026
tonghuaroot Credited to tonghuaroot
Style Dictionary - Prototype Pollution in convertTokenData utility function High
CVE-2026-54639 was published for style-dictionary (npm) Jul 28, 2026
Dremig Credited to Dremig and jorenbroekema jorenbroekema jorenbroekema
openhole-server vulnerable to path traversal via URL-decoded request path High
CVE-2026-54650 was published for github.com/bablilayoub/openhole (Go) Jul 28, 2026
MrSmiiith Credited to MrSmiiith
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution Critical
CVE-2026-54658 was published for @hypequery/clickhouse (npm) Jul 28, 2026
cobyge Credited to cobyge
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
goshs has a Path Traversal issue Moderate
CVE-2026-66063 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite Critical
CVE-2026-64863 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
anir0y Credited to anir0y
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) Critical
CVE-2026-62325 was published for github.com/patrickhener/goshs/v2 (Go) Jul 28, 2026
yukikamome316 Credited to yukikamome316
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field High
CVE-2026-54653 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding High
CVE-2026-55391 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default) High
CVE-2026-54690 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn, mhamzakhattak, and Muzammilxi mhamzakhattak mhamzakhattak
Muzammilxi Muzammilxi
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description High
CVE-2026-54621 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects High
CVE-2026-54691 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability High
CVE-2026-32203 was published for System.Security.Cryptography.Xml (NuGet) Jul 28, 2026
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass Moderate
CVE-2026-52888 was published for @nocobase/plugin-collection-sql (npm) Jul 28, 2026
lucquach Credited to lucquach
ProTip! Advisories are also available from the GraphQL API