Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

70 advisories

Loading
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin Moderate
CVE-2026-69215 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, ERobertGII, and samspills ERobertGII ERobertGII
samspills samspills
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain Moderate
CVE-2026-69214 was published for org.http4s:http4s-client_2.12 (Maven) Sep 15, 2026
rossabaker Credited to rossabaker, samspills, and morgen-peschke samspills samspills
morgen-peschke morgen-peschke
Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the... High Unreviewed
CVE-2026-53871 was published Jun 17, 2026
Concrete CMS is vulnerable to IDOR in surveys Moderate
CVE-2026-8337 was published for concrete5/concrete5 (Composer) May 22, 2026
mabjr33 Credited to mabjr33
sm1ee Credited to sm1ee, ioquatix, and jeremyevans ioquatix ioquatix
jeremyevans jeremyevans
github.com/gitpod-io/gitpod vulnerable to Cookie Tossing Moderate
CVE-2024-21583 was published for github.com/gitpod-io/gitpod (Go) Jul 19, 2024
ProTip! Advisories are also available from the GraphQL API