Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,573 advisories

Loading
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE High
CVE-2026-88975 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
stasimus Credited to stasimus and rossabaker rossabaker rossabaker
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake High
CVE-2026-61544 was published for libp2p-quic (Rust) Sep 15, 2026
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators Moderate
CVE-2026-69201 was published for org.http4s:http4s-server_2.12 (Maven) Sep 15, 2026
Lasering Credited to Lasering, rossabaker, and samspills rossabaker rossabaker
samspills samspills
Http4s Ember HTTP/2: unbounded continuation frame accumulation High
CVE-2026-69218 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, morgen-peschke, and reardonj samspills samspills
morgen-peschke morgen-peschke reardonj reardonj
Http4s: Ember chunk parser lenience (TE.TE request smuggling) Moderate
CVE-2026-69216 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII, rossabaker, and morgen-peschke rossabaker rossabaker
morgen-peschke morgen-peschke
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin Moderate
CVE-2026-69215 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, ERobertGII, and samspills ERobertGII ERobertGII
samspills samspills
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain Moderate
CVE-2026-69214 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Http4s Ember HTTP/2 has an unbounded outbound frame queue High
CVE-2026-69213 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
Http4s: DigestAuth nonce map grows unbounded High
CVE-2026-69208 was published for org.http4s:http4s-ember-server_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Http4s: DigestAuth allows replay of captured requests Moderate
CVE-2026-69206 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker and morgen-peschke morgen-peschke morgen-peschke
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling) High
CVE-2026-69205 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) Critical
CVE-2026-69204 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS High
CVE-2026-69203 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
reardonj Credited to reardonj and rossabaker rossabaker rossabaker
Http4s Ember HTTP/2: unbounded inbound body buffering High
CVE-2026-69202 was published for org.http4s:http4s-ember-core_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker and reardonj reardonj reardonj
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty Low
GHSA-rf68-8gjr-36q7 was published for github.com/nezhahq/nezha (Go) Sep 15, 2026
DavidCarliez Credited to DavidCarliez
Netmaker has a boolean‑based SQL Injection Moderate
CVE-2026-32599 was published for github.com/gravitl/netmaker (Go) Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions Moderate
CVE-2026-76081 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
AyushParkara Credited to AyushParkara, IAM-marco, and livio-a IAM-marco IAM-marco
livio-a livio-a
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange High
CVE-2026-56668 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
thesecguy45 Credited to thesecguy45, cipher-creator, and wim07101993 cipher-creator cipher-creator
wim07101993 wim07101993
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade Critical
CVE-2026-59178 was published for esphome-device-builder (pip) Sep 14, 2026
mmomjian Credited to mmomjian
October CMS: Incomplete Scheme Validation in Image Resizer Low
GHSA-2xmm-m4wv-3fjh was published for october/october (Composer) Sep 14, 2026
0xGenesi Credited to 0xGenesi
October CMS: PHP Object Injection via Backend Widget Session Storage Low
CVE-2026-49400 was published for october/system (Composer) Sep 14, 2026
EndlssNightmare Credited to EndlssNightmare
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls Low
CVE-2026-46696 was published for october/system (Composer) Sep 14, 2026
r00tn0b0dy Credited to r00tn0b0dy
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
ProTip! Advisories are also available from the GraphQL API