-
Notifications
You must be signed in to change notification settings - Fork 729
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-v9v8-jp27-55gf] marimo before 0.23.15 contains a configuration injection...
#9202
opened Aug 25, 2026 by
Grg0rry
Loading…
[GHSA-4p9m-8gc4-rw2h] GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
#9201
opened Aug 25, 2026 by
tristanmorgan
Loading…
[GHSA-9xq9-36w5-q796] lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
#9200
opened Aug 24, 2026 by
antonisloukis
Loading…
[GHSA-xm8c-hvjf-c5q9] npm-check-updates through 23.0.2, fixed in commit b554b84...
#9199
opened Aug 24, 2026 by
antonisloukis
Loading…
[GHSA-68j8-pq59-fqgm] NLTK has a Path Traversal issue
#9198
opened Aug 24, 2026 by
antonisloukis
Loading…
[GHSA-698x-9w2p-7vvp] Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
#9197
opened Aug 24, 2026 by
hdonnay
Loading…
[GHSA-9x9x-v3ff-pj74] Add strix-agent PyPI package mapping
#9195
opened Aug 24, 2026 by
LKA09
Loading…
[GHSA-rf74-v2fm-23pw] Add nltk 3.9.4 fix commit and patched version
#9193
opened Aug 23, 2026 by
SebTardif
Loading…
[GHSA-v7cf-c9rm-wm3j] Add CVE-2026-9769 and justhtml 1.10.0 fix commits
#9192
opened Aug 23, 2026 by
SebTardif
Loading…
[GHSA-q63x-9pfm-mjx4] Feast before 0.63.0 contains an unsafe deserialization...
#9191
opened Aug 23, 2026 by
PercevalFox
Loading…
[GHSA-x3f8-2w95-hw4m] ChangeDetection.io versions prior to 0.54.7 contain a...
#9190
opened Aug 23, 2026 by
PercevalFox
Loading…
[GHSA-v9v8-jp27-55gf] marimo before 0.23.15 contains a configuration injection...
#9189
opened Aug 23, 2026 by
PercevalFox
Loading…
[GHSA-rrh3-cwwj-g5mg] Cornac before 2.6.0 contains a path traversal (Tar Slip)...
#9188
opened Aug 23, 2026 by
PercevalFox
Loading…
[GHSA-8q5r-mmjf-575q] Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
#9187
opened Aug 22, 2026 by
antonisloukis
Loading…
[GHSA-6w46-j5rx-g56g] pytest has vulnerable tmpdir handling
#9186
opened Aug 22, 2026 by
colinxu2020
Loading…
[GHSA-597g-3phw-6986] virtualenv: align described fixed version with the recorded range (fixed in 20.36.1, not 20.36.2)
#9185
opened Aug 22, 2026 by
pacocartones
Loading…
[GHSA-9mc5-qgxh-72q4] Mescius ActiveReports.NET TypeResolutionService...
#9184
opened Aug 22, 2026 by
Alechilles
Loading…
[GHSA-5g29-3f8w-5892] Mescius ActiveReports.NET ReadValue Deserialization of...
#9183
opened Aug 22, 2026 by
Alechilles
Loading…
[GHSA-vgq7-9r5r-j9v3] Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API
#9182
opened Aug 21, 2026 by
riccardopreatoni
Loading…
[GHSA-6w3v-mcfh-m3q7] Keycloak Admin UI REST Extensions: bulk role-removal endpoints fail to perform granular permission checks
#9180
opened Aug 21, 2026 by
eminaktas
Loading…
[GHSA-6g26-7cx5-mrrg] Keycloak: Information disclosure due to user profile permission bypass
#9179
opened Aug 21, 2026 by
eminaktas
Loading…
[GHSA-852m-cvvp-9p4w] Add missing Wasmtime 41.x range and correct CVSS v4
#9177
opened Aug 20, 2026 by
KirilsTurkins
Loading…
[GHSA-w4pp-8pjf-rmxw] Versions of the package pacote from 11.2.7 are vulnerable...
#9176
opened Aug 20, 2026 by
zain-ul-abideen-5036
Loading…
[GHSA-4x29-79gh-6v8q] Detection of Error Condition Without Action vulnerability...
#9175
opened Aug 20, 2026 by
vanxa
Loading…
[GHSA-p93r-85wp-75v3] Correct Bouncy Castle package version ranges
#9172
opened Aug 20, 2026 by
ECD5A
Loading…
Previous Next
ProTip!
Follow long discussions with comments:>50.