-
Notifications
You must be signed in to change notification settings - Fork 686
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-x3f8-2w95-hw4m] ChangeDetection.io before 0.54.7 allows arbitrary file read via unblocked XPath functions
#8864
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-m3px-q5gj-j9x7] kafka-python before 2.3.2 is vulnerable to memory exhaustion in the protocol parser
#8863
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-hqp4-2352-xf5r] Keras before 3.14.0 is vulnerable to path traversal during archive extraction
#8862
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-8cjm-8mp7-r2xf] Django 5.2 before 5.2.15 and 6.0 before 6.0.6 store cached responses with case-varied Cache-Control directives
#8861
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-2jcm-hq8r-84wx] kafka-python before 2.3.2 is vulnerable to denial of service via an unvalidated SCRAM iteration count
#8860
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
#8858
opened Jul 29, 2026 by
erkro1
Loading…
[GHSA-crf3-v9rr-v7hj] Fix package mapping for CVE-2026-16723 Fastjson2 RCE
#8857
opened Jul 28, 2026 by
AnvithaCDhanekula
Loading…
[GHSA-52cp-r559-cp3m] js-yaml: YAML merge-key chains can force quadratic CPU consumption
#8856
opened Jul 28, 2026 by
SkyeCyclone
Loading…
[GHSA-2gh3-rmm4-6rq5] Crash due to uncontrolled recursion in protobuf crate
#8853
opened Jul 28, 2026 by
benholl94-cmyk
Loading…
[GHSA-4h8f-2wvx-gg5w] Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
#8850
opened Jul 28, 2026 by
tal-sealsecurity
Loading…
[GHSA-crf3-v9rr-v7hj] A remote code execution (RCE) vulnerability exists in...
#8849
opened Jul 28, 2026 by
dor-hayun
Loading…
[GHSA-792x-6vq6-j8r9] Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
#8848
opened Jul 28, 2026 by
oleg-andreev-check24
Loading…
[GHSA-h738-vh6g-q8gh] OS command injection in the npm package loading component...
#8847
opened Jul 28, 2026 by
Franklyn-R-Silva
Loading…
[GHSA-v9x8-262p-f2g5] Allocation of Resources Without Limits or Throttling...
#8845
opened Jul 28, 2026 by
Franklyn-R-Silva
Loading…
[GHSA-f37p-pc7r-rghm] Allocation of resources without limits vulnerability in...
#8844
opened Jul 28, 2026 by
Franklyn-R-Silva
Loading…
[GHSA-792x-6vq6-j8r9] Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
#8840
opened Jul 28, 2026 by
ChristianAchatz
Loading…
[GHSA-f2m9-wcf4-cwwx] MLFlow Creates a Temporary File With Insecure Permissions
#8839
opened Jul 28, 2026 by
Chi-Song-Owen
Loading…
[GHSA-jpjm-c3r5-q96r] A norm.Iter can enter an infinite loop when handling...
#8838
opened Jul 28, 2026 by
pbettadapura
Loading…
[GHSA-3qwc-47jf-5rf7] Add CWE-1285 for improper ABI pointer validation
#8837
opened Jul 28, 2026 by
yhay81
Loading…
[GHSA-h738-vh6g-q8gh] Add jsii-diff package and affected range
#8836
opened Jul 28, 2026 by
yhay81
Loading…
[GHSA-cpmr-mw4j-99r7] Add CWE-22 for Label Studio path traversal
#8834
opened Jul 28, 2026 by
yhay81
Loading…
[GHSA-hj8m-9fhf-v7jp] Add CWE-1336 for fief-server SSTI
#8833
opened Jul 27, 2026 by
yhay81
Loading…
Previous Next
ProTip!
Type g p on any issue or pull request to go back to the pull request listing page.