-
Notifications
You must be signed in to change notification settings - Fork 682
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-mh99-v99m-4gvg] brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
#8832
opened Jul 27, 2026 by
G-Rath
Loading…
[GHSA-x744-4wpc-v9h2] Moby has AuthZ plugin bypass when provided oversized request bodies
#8830
opened Jul 27, 2026 by
praneethd51
Loading…
[GHSA-792x-6vq6-j8r9] Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
#8829
opened Jul 27, 2026 by
oleg-andreev-check24
Loading…
[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
#8828
opened Jul 27, 2026 by
AlexGustafsson
Loading…
[GHSA-vf77-8h7g-gghp] Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
#8827
opened Jul 27, 2026 by
aruneko
Contributor
Loading…
GHSA-x9hg-5q6g-q3jr: set fixed version to 0.14.3 (CVE-2025-51471)
#8826
opened Jul 27, 2026 by
nghiadaulau
Loading…
GHSA-frvp-7c67-39w9: 1.x line was patched in 1.19.15, not only 2.0.5
#8824
opened Jul 26, 2026 by
askalf
Loading…
[GHSA-78fc-9688-w8xw] Fix malformed CVSS 4 vector
#8819
opened Jul 26, 2026 by
mohammadrezwankhan
Loading…
[GHSA-fgcw-684q-jj6r] huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
#8812
opened Jul 25, 2026 by
daemon
Loading…
[GHSA-83x9-8wvq-rrcp] The urwid web display backend (urwid/display/web.py)...
#8809
opened Jul 24, 2026 by
penguinolog
Loading…
[GHSA-vqqj-9cmv-hx43] Undertow is Vulnerable to HTTP Request/Response Smuggling
#8807
opened Jul 24, 2026 by
julianladisch
Loading…
[GHSA-3gv6-g396-9v4r] Undertow is Vulnerable to HTTP Request/Response Smuggling
#8806
opened Jul 24, 2026 by
julianladisch
Loading…
[GHSA-8v4x-mgvp-p658] Undertow is Vulnerable to HTTP Request/Response Smuggling
#8805
opened Jul 24, 2026 by
julianladisch
Loading…
[GHSA-6hcw-qqr8-pjj8] Apache Airflow: Authenticated users can bypass the
is_safe_url check
#8804
opened Jul 24, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-q2hg-643c-gw8h] Apache Airflow: RCE by race condition in example_xcom dag
#8803
opened Jul 24, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-2r5m-76wx-56gx] Apache Airflow Vulnerable to Deserialization of Untrusted Data
#8802
opened Jul 24, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-2r2c-cx56-8933] JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
#8801
opened Jul 24, 2026 by
j-zygmunt
Loading…
[GHSA-47qp-hqvx-6r3f] JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
#8800
opened Jul 24, 2026 by
j-zygmunt
Loading…
[GHSA-p7mv-53f2-4cwj] CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
#8797
opened Jul 23, 2026 by
simonmorley
Loading…
[GHSA-pvx3-gm3c-gmpr] Denial of Service in Go-Ethereum
#8796
opened Jul 23, 2026 by
simonmorley
Loading…
[GHSA-gf47-qgg5-9g9q] Improper Validation of Certificate with Host Mismatch...
#8795
opened Jul 23, 2026 by
Ankush-Pathak
Contributor
Loading…
[GHSA-m4p7-r5rc-7g4j] pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
#8792
opened Jul 23, 2026 by
westonsteimel
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.