-
Notifications
You must be signed in to change notification settings - Fork 731
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-cvhv-g4rq-3hmw] Add upstream fix commit reference
#9322
opened Sep 2, 2026 by
Junaid-PK
Loading…
[GHSA-mgvc-8q2h-5pgc] Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
#9321
opened Sep 2, 2026 by
shaked-seal
Loading…
[GHSA-jwv3-5hgf-82ww] python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
#9320
opened Sep 2, 2026 by
frenzymadness
Loading…
[GHSA-6956-f2gq-2c74] The extension passes the raw value of a form field...
#9319
opened Sep 2, 2026 by
cweiske
Loading…
[GHSA-693x-mfgg-48mq] Improper neutralization of input during web page generati...
#9311
opened Sep 2, 2026 by
oscerd
Loading…
[GHSA-5445-5xcv-f4gr] Improper neutralization of input during web page generati...
#9310
opened Sep 2, 2026 by
oscerd
Loading…
[GHSA-298h-94gv-3jfv] ResourceIsolationRequestCycleListener protects a Wicket a...
#9309
opened Sep 2, 2026 by
oscerd
Loading…
[GHSA-c9ff-59g8-m36q] A flaw was found in Jolokia's JSR-160 proxy functionality...
#9308
opened Sep 2, 2026 by
grgrzybek
Loading…
[GHSA-xvcm-6775-5m9r] Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
#9307
opened Sep 2, 2026 by
ravali-ch15
Loading…
[GHSA-72q8-9rgw-5g6j] Improper TLS hostname verification vulnerability in...
#9306
opened Sep 2, 2026 by
mcr-paulanand
Loading…
[GHSA-gjhq-gjfw-99mq] The source-address critical option in the Permissions...
#9305
opened Sep 1, 2026 by
kbsteere
Loading…
[GHSA-f97h-2pfx-f59f] HTTP response splitting in uvicorn
#9304
opened Sep 1, 2026 by
hamedrabah
Loading…
[GHSA-2cqg-q7jm-j35c] snipe-it is vulnerable to Cross-site Scripting
#9302
opened Sep 1, 2026 by
nikpivkin
Loading…
[GHSA-526f-jxpj-jmg2] Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption
#9300
opened Sep 1, 2026 by
kgnio
Loading…
[GHSA-mpx4-jmpr-vm8v] PGHoard: Password written to debug log
#9298
opened Sep 1, 2026 by
kgnio
Loading…
[GHSA-ch4j-vcf5-58x5] Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option
#9297
opened Sep 1, 2026 by
kgnio
Loading…
[GHSA-4w3x-69m8-478c] A flaw was found in the role-users endpoint of the...
#9296
opened Sep 1, 2026 by
ottotouzil
Loading…
[GHSA-v4g2-cm5v-cxv7] Digital products download without proper payment status check
#9295
opened Sep 1, 2026 by
nikpivkin
Loading…
Previous Next
ProTip!
no:milestone will show everything without a milestone.