Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
zbateson/mail-mime-parser has CRLF header injection via attachment filename High
CVE-2026-61815 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
iliaal Credited to iliaal
Grav: Unauthenticated denial of service via unbounded image derivative dimensions High
CVE-2026-53653 was published for getgrav/grav (Composer) Aug 14, 2026
iliaal Credited to iliaal
Composer: Arbitrary file write outside vendor via malicious transitive package name High
CVE-2026-59948 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
ProTip! Advisories are also available from the GraphQL API