Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9,356 advisories

Loading
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher Low
CVE-2026-84298 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
Phaxma Credited to Phaxma
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope Low
CVE-2026-77637 was published for github.com/cloudreve/Cloudreve/v4 (Go) Sep 22, 2026
de3erve-hunter Credited to de3erve-hunter
Unleash: Missing await on permission check + cross-project IDOR in admin API High
CVE-2026-77426 was published for unleash-server (npm) Sep 22, 2026
crazydude123 Credited to crazydude123
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass High
CVE-2026-77243 was published for mcp-atlassian (pip) Sep 22, 2026
0xmagic0 Credited to 0xmagic0
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards Moderate
CVE-2026-69190 was published for org.graylog2:graylog2-server (Maven) Sep 22, 2026
kah-ja Credited to kah-ja
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes High
CVE-2026-63116 was published for @deepstream/server (npm) Sep 22, 2026
manus-use Credited to manus-use
MISP contains an access control flaw in the EventReports functionality. The... Moderate Unreviewed
CVE-2026-95685 was published Sep 22, 2026
ProTip! Advisories are also available from the GraphQL API