Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

76 advisories

Loading
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion Moderate
CVE-2026-11748 was published for com.linecorp.centraldogma:centraldogma-server-auth-shiro (Maven) Sep 11, 2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')... Moderate Unreviewed
CVE-2026-81205 was published Sep 2, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with... Moderate Unreviewed
CVE-2026-76373 was published Aug 20, 2026
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP)... Moderate Unreviewed
CVE-2026-74241 was published Aug 15, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability High
CVE-2026-47303 was published for Microsoft.AspNetCore.Authentication.Negotiate (NuGet) Jul 21, 2026
OpenAM Authentication Bypass via MSISDN LDAP Injection High
CVE-2026-46619 was published for org.openidentityplatform.openam:openam-auth-msisdn (Maven) Jun 26, 2026
wodzen Credited to wodzen
OpenBao: LDAPi ldaputil (wrong escape func) Moderate
CVE-2026-55770 was published for github.com/openbao/openbao (Go) Jun 19, 2026
alcls01111 Credited to alcls01111
Apache Shiro: LDAP DN Injection in DefaultLdapRealm High
CVE-2026-49268 was published for org.apache.shiro:shiro-core (Maven) Jun 17, 2026
Yamcs Vulnerable to LDAP Injection in LdapAuthModule Moderate
CVE-2026-42568 was published for org.yamcs:yamcs-core (Maven) May 26, 2026
ex-cal1bur Credited to ex-cal1bur
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability Moderate
CVE-2026-46745 was published for apache-airflow-providers-fab (pip) May 26, 2026
Apache CXF has an LDAP injection vulnerability Critical
CVE-2026-44930 was published for org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (Maven) May 26, 2026
ProTip! Advisories are also available from the GraphQL API