Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,567 advisories

Loading
SWC HTML minifier may allow script element breakout when minifying embedded JSON Moderate
CVE-2026-72925 was published for @swc/html (npm) Sep 8, 2026
j9t Credited to j9t
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions Moderate
CVE-2026-63733 was published for surrealdb-core (Rust) Sep 4, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval High
CVE-2026-75912 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning Critical
CVE-2026-75856 was published for codewhale (npm) Sep 4, 2026
JafarAkhondali Credited to JafarAkhondali
CodeWhale: js_execution leaks parent environment to model context via missing env scrub High
CVE-2026-75915 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
SurrealDB allows bypass of deny-net flags via DNS resolution Moderate
CVE-2025-71390 was published for SurrealDB (Rust) Sep 4, 2026
manelmontilla Credited to manelmontilla
Hurl: Cookies in Cookies section leak when redirecting to a different host Moderate
CVE-2026-63481 was published for hurl (Rust) Sep 2, 2026
p80n-sec Credited to p80n-sec
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref Moderate
CVE-2026-55406 was published for buffa (Rust) Aug 28, 2026
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS High
CVE-2026-54788 was published for datadog-opentelemetry (Rust) Aug 28, 2026
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) Moderate
GHSA-2vh6-hw4j-32ww was published for gix-packetline (Rust) Aug 28, 2026
KutalVolkan Credited to KutalVolkan
Wasmtime has a leak in WASIp1 `fd_renumber` implementation Low
CVE-2026-54786 was published for wasmtime-wasi (Rust) Aug 26, 2026
alexcrichton Credited to alexcrichton
geo-chen Credited to geo-chen
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service Moderate
GHSA-3gjw-f78c-vvpw was published for tokio-postgres (Rust) Aug 24, 2026
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Moderate
GHSA-rgqc-3x5p-6gwg was published for postgres-protocol (Rust) Aug 24, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service High
GHSA-5x78-73v4-xg6w was published for postgres-protocol (Rust) Aug 24, 2026
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl Moderate
GHSA-mc9m-6fm9-pghc was published for kcl-lib (pip) Aug 20, 2026
maxammann Credited to maxammann
ProTip! Advisories are also available from the GraphQL API