-
Notifications
You must be signed in to change notification settings - Fork 725
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-8q5r-mmjf-575q] Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
#9187
opened Aug 22, 2026 by
antonisloukis
Loading…
[GHSA-6w46-j5rx-g56g] pytest has vulnerable tmpdir handling
#9186
opened Aug 22, 2026 by
colinxu2020
Loading…
[GHSA-597g-3phw-6986] virtualenv: align described fixed version with the recorded range (fixed in 20.36.1, not 20.36.2)
#9185
opened Aug 22, 2026 by
pacocartones
Loading…
[GHSA-9mc5-qgxh-72q4] Mescius ActiveReports.NET TypeResolutionService...
#9184
opened Aug 22, 2026 by
Alechilles
Loading…
[GHSA-5g29-3f8w-5892] Mescius ActiveReports.NET ReadValue Deserialization of...
#9183
opened Aug 22, 2026 by
Alechilles
Loading…
[GHSA-vgq7-9r5r-j9v3] Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API
#9182
opened Aug 21, 2026 by
riccardopreatoni
Loading…
[GHSA-6w3v-mcfh-m3q7] Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
#9180
opened Aug 21, 2026 by
eminaktas
Loading…
[GHSA-6g26-7cx5-mrrg] Keycloak: Information disclosure due to user profile permission bypass
#9179
opened Aug 21, 2026 by
eminaktas
Loading…
[GHSA-852m-cvvp-9p4w] Add missing Wasmtime 41.x range and correct CVSS v4
#9177
opened Aug 20, 2026 by
KirilsTurkins
Loading…
[GHSA-w4pp-8pjf-rmxw] Versions of the package pacote from 11.2.7 are vulnerable...
#9176
opened Aug 20, 2026 by
zain-ul-abideen-5036
Loading…
[GHSA-4x29-79gh-6v8q] Detection of Error Condition Without Action vulnerability...
#9175
opened Aug 20, 2026 by
vanxa
Loading…
[GHSA-p93r-85wp-75v3] Correct Bouncy Castle package version ranges
#9172
opened Aug 20, 2026 by
ECD5A
Loading…
Correct Apollo Portal package scope for GHSA-jxpj-9j24-w337
#9169
opened Aug 20, 2026 by
nobodyiam
Loading…
Correct Apollo ConfigService package scope for GHSA-h4pc-58cc-hc95
#9168
opened Aug 20, 2026 by
nobodyiam
Loading…
Correct Apollo ConfigService package scope for GHSA-4w3q-qpfq-v992
#9167
opened Aug 20, 2026 by
nobodyiam
Loading…
[GHSA-2mhj-fhvg-v428] Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
#9166
opened Aug 20, 2026 by
astapc
Loading…
[GHSA-8qqm-fp2q-v734] Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
#9162
opened Aug 19, 2026 by
deepakravisankar
Loading…
[GHSA-jjmj-jmhj-qwj2] React Router: Open redirect leading to XSS
#9156
opened Aug 18, 2026 by
brophdawg11
Loading…
[GHSA-pv39-qrfq-g8gc] In nltk version 3.9.4, the `nltk.downloader.Downloader...
#9155
opened Aug 18, 2026 by
navaneethibm
Loading…
[GHSA-3p64-6gvh-82v5] MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
#9154
opened Aug 18, 2026 by
noren95
Loading…
[GHSA-876p-8259-xjgg] libp2p nodes vulnerable to attack using large RSA keys
#9151
opened Aug 17, 2026 by
simonmorley
Loading…
[GHSA-x863-p983-p4f7] In an untrusted JMS environment, org.springframework.jms...
#9140
opened Aug 17, 2026 by
tal-sealsecurity
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.