Security advisories — page 9
- GHSA-89hf-xcx5-r9r6mediumDuplicate Advisory: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos disc
- GHSA-8wx9-j7j5-h9vphighDuplicate Advisory: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachabil
- GHSA-v598-7627-g9fxcriticalDuplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level cont
- GHSA-h4w7-mgq4-wg6xmediumDuplicate Advisory: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attr
- GHSA-72xp-24p9-7vpfmediumDuplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath
- GHSA-j26h-r8jx-887cmediumDuplicate Advisory: Password (protected) tier omitted in the attribute-view/database publish filter: Reader re
- GHSA-mhcc-g592-267jmediumDuplicate Advisory: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of fo
- GHSA-2jmx-q9jf-wp3whighDuplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malic
- GHSA-2qqv-3jgq-vpm9criticalDuplicate Advisory: Non-administrator responses from /api/system/getConf omit three secrets that the configura
- GHSA-fxmw-rv85-5hwhmediumDuplicate Advisory: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema
- GHSA-xx34-6cjg-prh8criticalDuplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allo
- GHSA-v3v5-7j3j-cc6fmediumDuplicate Advisory: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private
- GHSA-rchc-g58m-88jmmediumDuplicate Advisory: getEncryptedNotebookStatus discloses names and live unlock state of all encrypted notebook
- GHSA-mxjf-vfmv-qfm6mediumDuplicate Advisory: Notebook name, document count, size and timestamps are returned for any notebook, includin
- GHSA-cjwm-9h7g-pcr9criticalDuplicate Advisory: Embedded (transclusion) block content is returned without publish-access filtering, leakin
- GHSA-cm9f-w4h4-7j85mediumDuplicate Advisory: Static-file routes bypass the publish-access controls enforced on the REST API, exposing t
- GHSA-mg8q-52j3-w5f8criticalDuplicate Advisory: Publish-access filter on renderAttributeView leaves related-database content unfiltered an
- GHSA-f68g-4xv8-2g75mediumDuplicate Advisory: Tag labels from password-protected documents are returned to readers who have not entered
- GHSA-hg4j-w33m-p7g4criticalDuplicate Advisory: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/s
- GHSA-hr3f-qfrh-h7w5highDuplicate Advisory: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymou
- GHSA-pfvm-w89x-94jwhighSIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay f
- GHSA-jwjp-4649-v8jphighSIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
- CVE-2026-55071highMCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
- CVE-2026-52776highCVE-2026-52776 updated by NVD
- CVE-2026-47132mediumphpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
- CVE-2026-46369highCVE-2026-46369 updated by NVD
- CVE-2026-45694mediumCVE-2026-45694 updated by NVD
- CVE-2026-35445highCVE-2026-35445 updated by NVD
- CVE-2026-32639mediumCVE-2026-32639 updated by NVD
- CVE-2026-32593mediumCVE-2026-32593 updated by NVD
- CVE-2026-32258highCVE-2026-32258 updated by NVD
- CVE-2026-32257highCVE-2026-32257 updated by NVD
- GHSA-2q33-cf8w-7q23criticalDuplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability
- GHSA-4hc4-qjfx-wjf3criticalDuplicate Advisory: Craft CMS: Authorization bypass: view-only Categories user can modify category structure v
- GHSA-9w6w-8x3c-hfqpmediumDuplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal
- GHSA-cc2g-26rw-g997highDuplicate Advisory: Craft CMS: Authenticated leak of secret environment variables
- GHSA-h784-hpjp-2rrmhighDuplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape
- GHSA-w36c-qxrq-v7fwhighDuplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
- GHSA-2p2v-3mjg-gfpfhighDuplicate Advisory: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
- GHSA-4jjw-pwvw-q6w3mediumDuplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspac
- GHSA-4f2f-jr2m-j7p4highDuplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool
- GHSA-jm78-9fvv-mhgrhighGitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.s
- GHSA-55q2-fjhq-7xh7mediumDOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
- GHSA-wg23-69c2-gjc8criticalCraft CMS: Passkey login accepts replayed WebAuthn assertions
- GHSA-2rp4-x2j7-qmccmediumCraft CMS: Stored XSS in the control panel via unescaped draft name
- GHSA-w9hm-4m3m-fxmmhighngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
- CVE-2026-16633highPDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
- GHSA-p8x7-9vfw-p7vchighCraft CMS: Arbitrary user password reset leading to administrator account takeover
- GHSA-mj63-m3rc-8pprmediumleague/commonmark: Denial of service via deeply nested XML output
- GHSA-mh25-x5hq-wrqphighleague/commonmark: Denial of service via colliding heading slugs
- GHSA-jfm3-95jq-q3rfhighleague/commonmark: Denial of service via duplicate footnote definitions
- GHSA-g2gp-3wwq-f4phhighleague/commonmark: Denial of service via adjacent inline attribute blocks
- GHSA-5p4m-2wfm-xmqjhighJS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
- GHSA-gx4c-2hqx-cw2rlowrclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
- GHSA-h4mf-4v27-hggjmediumrclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
- GHSA-8mxv-9xhp-86h4mediumrclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
- GHSA-8v25-v8p6-qf7vmediumrclone: Path traversal in serve s3 allows reading and overwriting root-level files
- GHSA-3x6r-wxxg-53vvmediumrclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
- GHSA-945v-v9p3-v5xwlowrclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remot
- GHSA-gwfq-86j8-7qhvlowrclone: Verbose Stack Trace Disclosure in RC API Error Responses
- GHSA-8gj2-2cvc-6xx7mediumFlowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatf
- GHSA-rwrp-9823-p2xqmediumFlowise: Incomplete Credential Redaction Exposes Secrets via API
- GHSA-88pr-878c-24wfhighFlowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object ke
- GHSA-6qm2-mcq7-53qpmediumDuplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condi
- GHSA-2364-jh4q-m9vmmediumFlowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
- CVE-2026-69207mediumCVE-2026-69207 updated by NVD
- GHSA-p538-c434-8v24mediumGitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
- GHSA-539m-9xh6-q6rrmediumGitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbi
- GHSA-3f7w-8rr8-f37fhighGitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary
- GHSA-mmwh-j75q-gxp8highDuplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-
- GHSA-pqpf-6vqv-6w92criticalDuplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish
- GHSA-vj8j-973f-r65jhighDuplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static m
- GHSA-p2x7-4c4p-8wh6criticalDuplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reach
- GHSA-x7jr-gvvr-p9w7highDuplicate Advisory: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reac
- GHSA-g64v-qqpg-v37hcriticalDuplicate Advisory: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Tr
- GHSA-85xq-27m5-59m9criticalDuplicate Advisory: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction e
- GHSA-3rfw-7fxw-6jxmmediumDuplicate Advisory: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable docum
- GHSA-2mmh-4rf8-7xg6criticalDuplicate Advisory: SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mo
- GHSA-pv39-qrfq-g8gcmediumDuplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
- GHSA-3q45-2fh7-66cjcriticalDuplicate Advisory: better-auth has an external request basePath modification DoS
- GHSA-3fvr-2jw6-crq4mediumDuplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
- GHSA-mjrx-74jh-7xgwhighDuplicate Advisory: Guzzle: Host-only cookie scope is not preserved
- GHSA-mqq9-gxg5-m58ghighDuplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
- GHSA-32rq-jhr7-m3hhmediumDuplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
- GHSA-3mcp-22mf-vrw3mediumDuplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken
- GHSA-68jp-44vc-2x5hhighDuplicate Advisory: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
- GHSA-4vpg-pfj8-m33qhighDuplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote
- GHSA-6r2r-ww24-7h52highDuplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42
- GHSA-9wx3-p993-35vpmediumDuplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values
- GHSA-m4f3-g4cq-hqrxhighDuplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from()
- GHSA-cw2r-r7mw-j3hccriticalDuplicate Advisory: GitPython unsafe clone option gate bypass through joined short options
- GHSA-fq2j-3j99-rx65mediumDuplicate Advisory: Axios: Excessive recursion in formDataToJSON can cause denial of service
- GHSA-f2r5-pqh9-r8f8mediumDuplicate Advisory: Axios: Prototype pollution gadgets can alter axios request construction
- GHSA-7qf5-7ppr-87v8highDuplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication By
- GHSA-fqj3-h9pc-443hmediumDuplicate Advisory: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
- GHSA-38gx-cfqf-f652mediumDuplicate Advisory: Axios: Prototype pollution auth subfields can inject Basic auth
- GHSA-4ww2-rjh2-xpv9mediumDuplicate Advisory: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
- GHSA-39j5-w47m-2gmvmediumDuplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
- GHSA-6hqm-hm2v-3p2pmediumDuplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
- CVE-2016-1000305mediumguard-livereload has a directory traversal vulnerability
- GHSA-3whf-vgf2-9w6gmediumzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
- CVE-2026-12075highNatural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nlt
- CVE-2026-12061highNatural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
- CVE-2026-12072highNatural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses
- CVE-2026-12074highNatural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML f
- GHSA-p7w7-4929-vpj5high`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
- GHSA-xrmj-5g4g-8987medium@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
- GHSA-pqh8-p93p-2rx7medium@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
- GHSA-pmwx-rm49-xv39lowActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
- GHSA-xvg2-cgv6-6h7vhighnetfoil: Incorrect block responses could lead to localhost traffic
- GHSA-wchh-9x6h-7f6pmediumolm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
- GHSA-pc2w-4mq8-32qwlow@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
- GHSA-6xx4-9wp6-65p7mediumskilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
- CVE-2026-49446mediumCVE-2026-49446 updated by NVD
- CVE-2026-54632highCVE-2026-54632 updated by NVD
- GHSA-hc4m-q9jh-xw4jmediumnono-cli'scregistry pack verification can fail open when provenance metadata is absent
- GHSA-vg6v-j97m-h5xqmedium@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTT
- GHSA-hp74-gm6m-2qm5mediumPocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated
- CVE-2023-37465mediumorg.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to del
- GHSA-8q49-2h5h-434xmediumFrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
- CVE-2026-73502mediumCVE-2026-73502 updated by NVD
- GHSA-fp43-vj7g-pg92highOmniFaces: Forged combined-resource IDs and related output/push boundaries
- GHSA-p6ph-3jx2-3337mediumOpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
- CVE-2026-73494highCVE-2026-73494 updated by NVD
- GHSA-cmwh-g2h8-c222highPoweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
- GHSA-rm67-g9ch-vxffhighPoweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
- GHSA-h4hf-v6w5-897xhighPoweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuse
- GHSA-f25v-x6vr-962gcriticalPheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
- GHSA-v6w6-358x-2433mediumCloudreve Admin.Read OAuth tokens can trigger server-side node test requests
- GHSA-2625-rw7m-5q5xlowHubuum client library (Rust): Sensitive data may be exposed through default diagnostics
- GHSA-qqc3-94qv-7fw3mediumHubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network t
- GHSA-f45q-w629-wr25mediumHubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
- GHSA-c534-2w9c-x7fmmediumKite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
- GHSA-68r5-9hpg-7qw9criticalOpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
- GHSA-g3hq-hphg-8fhhhighPheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the m
- GHSA-94p4-4cq8-9g67highGitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GH
- CVE-2026-73410highCVE-2026-73410 updated by NVD
- GHSA-pmpg-2mxq-6xwrhighBudibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arb
- GHSA-pvcr-8mvp-w8qrhighBudibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
- GHSA-2xgg-r2wc-c5r2highBudibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
- GHSA-qw6m-8fw2-2v64highBudibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
- GHSA-mqhr-6j6h-74p5criticalBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
- CVE-2026-62323mediumCVE-2026-62323 updated by NVD
- CVE-2026-73302criticalCVE-2026-73302 updated by NVD
- GHSA-xg5g-26x8-cvf4highBudibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
- GHSA-xcx6-4f2g-hhgxhighBudibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObj
- CVE-2026-73304mediumCVE-2026-73304 updated by NVD
- CVE-2026-73305highCVE-2026-73305 updated by NVD
- CVE-2026-62379criticalCVE-2026-62379 updated by NVD
- CVE-2026-62280mediumCVE-2026-62280 updated by NVD
- CVE-2026-62263criticalCVE-2026-62263 updated by NVD
- CVE-2026-57497mediumCVE-2026-57497 updated by NVD
- CVE-2026-55502highCVE-2026-55502 updated by NVD
- CVE-2026-55499mediumCVE-2026-55499 updated by NVD
- CVE-2026-55497mediumCVE-2026-55497 updated by NVD
- CVE-2026-55496mediumCVE-2026-55496 updated by NVD
- CVE-2026-55495mediumCVE-2026-55495 updated by NVD
- CVE-2026-59714highCVE-2026-59714 updated by NVD
- GHSA-r277-6w6q-xmqwcriticalkin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
- GHSA-gcjh-h69q-9w9gmediumcel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
- CVE-2026-73489mediumCVE-2026-73489 updated by NVD
- GHSA-qwww-vcr4-c8h2highReact Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
- GHSA-464c-974j-9xm6lowAWS CDK CodeBuild S3 Log Encryption Boolean Inversion
- GHSA-r9mr-m37c-5fr3highGitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary c
- GHSA-6p8h-3wgx-97gfhighGitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution
- GHSA-fjr4-x663-mwxchighGitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-
- GHSA-w28w-gp39-m4p6criticalPrompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
- GHSA-3rp5-jjmw-4wv2highGitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
- CVE-2026-62946mediumCVE-2026-62946 updated by NVD
- CVE-2026-62363mediumCVE-2026-62363 updated by NVD
- CVE-2026-62343mediumCVE-2026-62343 updated by NVD
- CVE-2026-61632mediumCVE-2026-61632 updated by NVD
- CVE-2026-73428mediumCVE-2026-73428 updated by NVD
- CVE-2026-59952mediumCVE-2026-59952 updated by NVD
- CVE-2026-59940criticalCVE-2026-59940 updated by NVD
- CVE-2026-59949mediumCVE-2026-59949 updated by NVD
- GHSA-866w-xmhq-wj7xmediumSvelteKit: Prototype pollution in file input deletion path in remote-function forms
- GHSA-wqjv-9729-c5q2mediumSvelteKit: Big remote form function payloads can cause Node process to crash
- CVE-2026-63632lowCVE-2026-63632 updated by NVD
- GHSA-qq9h-g4jm-xgf3highBetter Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
- GHSA-h3rm-78g3-j7cphigh@better-auth/stripe: cross-organization billing tampering in organization subscription actions
- GHSA-rjg6-39jm-rgg4critical@better-auth/scim: account takeover and stale access via SCIM provider-id collision
- GHSA-76q6-2p6h-xjqrlowImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
- GHSA-h5r4-w88w-7ccrlowImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
- GHSA-h58x-r7f7-rh84lowImageMagick: Memory Leak in ICON decoder when allocation fails
- GHSA-m596-67p7-69whlowImageMagick: Memory leak in VIFF encoder when allocation fails
- GHSA-r628-69v2-2f9clowImageMagick: Memory Leak in MIFF encoder when allocaton fails
- GHSA-h7f2-f9cc-h2gvlowImageMagick: Memory Leak in YUV decoder when opening of blob fails
- GHSA-jfq9-q63x-rc63lowImageMagick: Memory Leak in TIFF encoder when an allocation fails
- GHSA-99w9-hv66-rfv7lowImageMagick: Memory Leak in JNG encoder when a blob could not be opened
- GHSA-j8rh-v2r8-v94xlowImageMagick: Memory Leak in hough lines operation when an operation fails
- GHSA-7c7m-fpjw-gwcqlowImageMagick: Memory Leak in color transformation to log colorspace when operation fails
- GHSA-6vxp-gfwf-hcr9lowImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
- GHSA-hwf3-r46v-5ggxlowImageMagick: Information Disclosure when printing profiles with debug enabled
- GHSA-qvxh-prvr-85w2lowImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
- GHSA-6jwg-7q3p-5fqmlowImageMagick: Use-After-Free when freetype initialization fails
- GHSA-vghg-5jrg-2398lowImageMagick: Policy Bypass in script operation due to missing checks
- GHSA-v3j6-27vc-7pw2lowImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
- GHSA-qh5g-q395-cx4jlowImageMagick: Heap-use-after-free via XMP profile could result in a crash
- GHSA-hc76-7mpc-qjqhmediumImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
- GHSA-56m6-8q75-f2rwmediumImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
- GHSA-rvhp-75f6-9jqhlowImageMagick: Policy Bypass possible with matrix-backed operations
- GHSA-4w2j-m93h-cj5jhighQuinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
- CVE-2026-55685highCVE-2026-55685 updated by NVD
- CVE-2026-53669mediumCVE-2026-53669 updated by NVD
- CVE-2026-53667mediumCVE-2026-53667 updated by NVD
- CVE-2026-53666mediumCVE-2026-53666 updated by NVD
- CVE-2026-47219highCVE-2026-47219 updated by NVD
- CVE-2026-45623highCVE-2026-45623 updated by NVD
- CVE-2026-59933highCVE-2026-59933 updated by NVD
- CVE-2026-59932highCVE-2026-59932 updated by NVD
- CVE-2026-59931highCVE-2026-59931 updated by NVD
- CVE-2026-73421criticalCVE-2026-73421 updated by NVD
- CVE-2026-73420criticalCVE-2026-73420 updated by NVD
- GHSA-pp9r-ppc4-25w4highDuplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data w
- GHSA-652q-gvq3-74qvmediumn8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
- GHSA-jqwr-vx3p-r266mediumn8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected Postg
- GHSA-9cmh-xcqm-5hqrmediumn8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
- CVE-2026-73417highCVE-2026-73417 updated by NVD
- CVE-2026-73416mediumCVE-2026-73416 updated by NVD
- GHSA-h5v5-8746-g7mmmediumJupyterLab PluginManager lock-rule enforcement bypass
- GHSA-whvh-wf3x-g77jlowJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (mis
- CVE-2026-64649highCVE-2026-64649 updated by NVD
- CVE-2026-64648mediumCVE-2026-64648 updated by NVD
- CVE-2026-64647mediumCVE-2026-64647 updated by NVD
- CVE-2026-64646mediumCVE-2026-64646 updated by NVD
- CVE-2026-64645highCVE-2026-64645 updated by NVD
- CVE-2026-64644mediumCVE-2026-64644 updated by NVD
- CVE-2026-64643mediumCVE-2026-64643 updated by NVD
- CVE-2026-64642highCVE-2026-64642 updated by NVD
- CVE-2026-64641highCVE-2026-64641 updated by NVD
- CVE-2026-59943mediumCVE-2026-59943 updated by NVD
- CVE-2026-59942mediumCVE-2026-59942 updated by NVD
- CVE-2026-59941mediumCVE-2026-59941 updated by NVD
- GHSA-pf2q-pxhf-hgmwmediumn8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
- GHSA-hx4h-vr3m-45vhmediumn8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
- GHSA-xwx6-jjhv-84p8highn8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
- GHSA-xmc9-4f2h-jf9chighn8n: Edit Image Node Format Injection Allows Arbitrary File Write
- GHSA-cj9h-qx8g-pq2ghighn8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
- GHSA-6qc9-mqvw-jg7xhighn8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
- GHSA-gv7g-jm28-cr3mhighn8n: Expression sandbox escape via arrow-function bodies enabling command execution
- GHSA-2x35-3fw4-9jr4highn8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
- GHSA-rcv6-pvrj-4xcghighn8n: Authenticated code execution in the n8n Git node
- GHSA-vhf8-cg2h-cg3pmediumn8n: SSRF Protection Bypass via MCP Client Node
- GHSA-gf29-4f56-r2jfhighn8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
- GHSA-64xh-79j6-r5v8highn8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
- GHSA-8342-988q-86crhighn8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
- CVE-2026-59921mediumCVE-2026-59921 updated by NVD
- CVE-2026-59920mediumCVE-2026-59920 updated by NVD
- CVE-2026-59919mediumCVE-2026-59919 updated by NVD
- CVE-2026-59901highCVE-2026-59901 updated by NVD
- CVE-2026-59900mediumCVE-2026-59900 updated by NVD
- CVE-2026-59899mediumCVE-2026-59899 updated by NVD
- CVE-2026-59898mediumCVE-2026-59898 updated by NVD
- CVE-2026-56822highCVE-2026-56822 updated by NVD
- CVE-2026-56821highCVE-2026-56821 updated by NVD
- CVE-2026-56722mediumCVE-2026-56722 updated by NVD
- CVE-2026-55555lowCVE-2026-55555 updated by NVD
- CVE-2026-55554lowCVE-2026-55554 updated by NVD
- GHSA-725q-c4vp-q4cghighDuplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Executi
- GHSA-mhvh-gwhr-76pwmediumDuplicate Advisory: Google Service Account Private Key Exposed in JWT Header
- GHSA-rhg6-2vjh-j5qchighDuplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
- GHSA-vhcw-f978-xjjghighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
- GHSA-7m3p-wc52-rmc6mediumDuplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
- GHSA-6mxq-jr92-3h2rmediumDuplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
- GHSA-wq64-hcrf-8m56highDuplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to T
- GHSA-88c4-pcqm-3r9pmediumDuplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
- GHSA-w46p-w7w2-fr9ghighDuplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
- GHSA-h5xr-fqvj-253phighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
- GHSA-fmvg-vhqq-r2mjmediumDuplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
- GHSA-mwq7-vcmc-cm4qhighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
- GHSA-h9fm-xcv2-qfw3mediumDuplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
- GHSA-m7jc-p4hf-xhwqhighDuplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
- GHSA-5vfw-jc4p-fj39mediumDuplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth
- GHSA-38fj-36m5-783cmediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
- GHSA-4v35-78jc-648rmediumDuplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows
- GHSA-f88m-g3jw-g9cjhighsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
- GHSA-hrxh-6v49-42gfhighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
- GHSA-5qhf-9phg-95m2lowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicol
- GHSA-r7wm-3cxj-wff9highjackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv
- CVE-2026-58429mediumCVE-2026-58429 updated by NVD
- CVE-2026-59765highCVE-2026-59765 updated by NVD
- CVE-2026-58511lowCVE-2026-58511 updated by NVD
- CVE-2026-57897mediumCVE-2026-57897 updated by NVD
- CVE-2026-58510mediumCVE-2026-58510 updated by NVD
- CVE-2026-58431mediumCVE-2026-58431 updated by NVD
- CVE-2026-58427highCVE-2026-58427 updated by NVD
- CVE-2026-58314highCVE-2026-58314 updated by NVD
- CVE-2026-58436highCVE-2026-58436 updated by NVD
- CVE-2026-56657mediumCVE-2026-56657 updated by NVD
- CVE-2026-58437highCVE-2026-58437 updated by NVD
- CVE-2026-55987highCVE-2026-55987 updated by NVD
- CVE-2026-58435mediumCVE-2026-58435 updated by NVD
- CVE-2026-58420mediumCVE-2026-58420 updated by NVD
- CVE-2026-55984lowCVE-2026-55984 updated by NVD
- CVE-2026-55982criticalCVE-2026-55982 updated by NVD
- CVE-2026-58434highCVE-2026-58434 updated by NVD
- CVE-2026-54481highCVE-2026-54481 updated by NVD
- CVE-2026-58417highCVE-2026-58417 updated by NVD
- CVE-2026-50105mediumCVE-2026-50105 updated by NVD
- CVE-2026-58416highCVE-2026-58416 updated by NVD
- CVE-2026-42931mediumCVE-2026-42931 updated by NVD
- CVE-2026-58445lowCVE-2026-58445 updated by NVD
- CVE-2026-58444mediumCVE-2026-58444 updated by NVD
- CVE-2026-58443criticalCVE-2026-58443 updated by NVD
- CVE-2026-58442mediumCVE-2026-58442 updated by NVD
- CVE-2026-58441mediumCVE-2026-58441 updated by NVD
- CVE-2026-58438highCVE-2026-58438 updated by NVD
- GHSA-rjvx-x5h2-6px5mediumGitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restri
- CVE-2026-56654criticalCVE-2026-56654 updated by NVD
- CVE-2026-56755mediumCVE-2026-56755 updated by NVD
- CVE-2026-58507mediumCVE-2026-58507 updated by NVD
- CVE-2026-57886mediumCVE-2026-57886 updated by NVD
- CVE-2026-23603lowCVE-2026-23603 updated by NVD
- CVE-2026-58425mediumCVE-2026-58425 updated by NVD
- CVE-2026-59763mediumCVE-2026-59763 updated by NVD
- CVE-2026-56750criticalCVE-2026-56750 updated by NVD
- CVE-2026-58432mediumCVE-2026-58432 updated by NVD
- CVE-2026-58428mediumCVE-2026-58428 updated by NVD
- CVE-2026-56443criticalCVE-2026-56443 updated by NVD
- CVE-2026-58439highCVE-2026-58439 updated by NVD
- CVE-2026-59766mediumGitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1
- CVE-2026-58440mediumCVE-2026-58440 updated by NVD
- GHSA-v396-v7q4-x2qjhighGitPython unsafe clone option gate bypass through joined short options
- GHSA-c2j3-45gr-mqc4lowDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
- GHSA-mhm7-754m-9p8wmediumjackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
- CVE-2026-57894highCVE-2026-57894 updated by NVD
- CVE-2026-61666highCVE-2026-61666 updated by NVD
- GHSA-frvp-7c67-39w9mediumNode.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
- GHSA-m464-hj36-96vxhighDuplicate Advisory: SurrealDB has Denial of Service in JSON parser due to nested objects
- GHSA-gw59-x2xr-wwvrmediumDuplicate Advisory: SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
- GHSA-mf42-3c8q-x7x8mediumDuplicate Advisory: SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live
- GHSA-4f9v-jpx9-mjvwhighDuplicate Advisory: SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
- GHSA-4q5r-gwcx-24m9highDuplicate Advisory: SurrealDB: Graph traversal bypasses table SELECT permissions
- GHSA-p7hp-79jj-q923mediumDuplicate Advisory: SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions
- GHSA-8pr5-wpg9-2h74mediumDuplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move
- GHSA-vq7c-3hc9-m5hrmediumDuplicate Advisory: SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
- GHSA-9c3h-q3pp-fw5xmediumDuplicate Advisory: SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
- GHSA-j6mj-v752-pp4xhighDuplicate Advisory: SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record
- GHSA-6g69-7xmf-h2x7mediumDuplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions
- GHSA-3f6w-45q9-v69mhighDuplicate Advisory: Custom API route lets authenticated callers override namespace/database scope via URL path
- GHSA-6g9r-xqrf-34xhlowDuplicate Advisory: SurrealDB no JavaScript script function default timeout could facilitate DoS
- GHSA-h5q3-3v5q-v5j8criticalDuplicate Advisory: SurrealDB server-takeover via SurrealQL injection on backup import
- GHSA-j9rh-f527-3x87highDuplicate Advisory: Improper Authorization in Select Permissions
- GHSA-f7q6-7rq9-3phxhighDuplicate Advisory: Uncaught Exception processing HTTP Headers in SurrealDB
- GHSA-vp9r-94xg-q7q8mediumDuplicate Advisory: SurrealDB allows bypass of deny-net flags via DNS resolution
- GHSA-xhwm-9486-8rgrmediumDuplicate Advisory: SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SS
- GHSA-hgp5-pm7v-q8vgmediumDuplicate Advisory: SurrealDB vulnerable to Improper Authentication when Changing Databases as Scope User
- GHSA-9qjc-q7hw-vw5rhighDuplicate Advisory: Uncaught Exception in Macro Expecting Native Function to Exist
- GHSA-9qrf-6whp-92w3mediumDuplicate Advisory: SurrealDB has an Uncaught Exception Handling Nonexistent Role
- GHSA-vmg6-53r4-jhpwlowDuplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
- GHSA-m8pp-qc66-6pgphighDuplicate Advisory: Full Table Permissions by Default
- GHSA-8qqm-fp2q-v734highSkipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
- GHSA-2f98-6626-h2p2mediumDuplicate Advisory: SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
- GHSA-7gcf-g7xr-8hxjmediumserde_with: KeyValueMap serialization panics on empty sequence or map entries
- GHSA-h738-vh6g-q8ghhighDuplicate Advisory: Command Injection in jsii-diff via npm: package argument
- GHSA-v626-428r-43p8highDuplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
- GHSA-373m-p57p-8665mediumDuplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
- GHSA-3j7v-fhjg-6rh2mediumDuplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
- GHSA-q6mx-qvhp-fqmgmediumDuplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch
- GHSA-p8pr-442q-qf8gmediumDuplicate Advisory: TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework
- GHSA-2vww-6p9h-5g8jmediumDuplicate Advisory: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
- GHSA-2qp2-6frj-p9pqmediumDuplicate Advisory: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression I
- GHSA-4wj4-79rr-pvffmediumDuplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitize
- GHSA-gqcv-rfj6-r29gmediumDuplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other
- GHSA-rqjw-r5g4-x8qmmediumDuplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Glo
- GHSA-rmj4-m9cp-mp9vmediumDuplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users access to user
- CVE-2026-49289highCVE-2026-49289 updated by NVD
- CVE-2026-49283highCVE-2026-49283 updated by NVD
- GHSA-gj2h-2fpw-fhv9medium@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydrati
- GHSA-q5h6-fcf5-49g9highDuplicate Advisory: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequenc
- CVE-2026-50029mediumCVE-2026-50029 updated by NVD
- GHSA-75mw-h36v-2jv7mediumDosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
- GHSA-f95g-vm94-46c3mediumDuplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
- GHSA-jcmp-jxh2-4jc3highDuplicate Advisory: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file re
- GHSA-24r3-p3x6-cqvxcriticalDuplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
- GHSA-5w9j-w5p8-r4p7mediumDuplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
- GHSA-xj2c-g5xp-4p47mediumDuplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transf
- GHSA-9r7j-7jhg-4f4cmediumDuplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
- GHSA-pmm4-v8f6-4vpphighDuplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
- GHSA-f4h3-qhg5-j6mqmediumDuplicate Advisory: Craft CMS: Authorized asset "preview file" requests bypass allows users without
- GHSA-fcqg-3mwf-cfcfhighDuplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx
- GHSA-qvp4-q2p5-22gghighDuplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load
- GHSA-8mc5-7w9m-fqv6highDuplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInter
- GHSA-fh2f-24rh-r2vqhighDuplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()
- GHSA-xj9w-cgqg-q897mediumDuplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
- GHSA-78fp-cf4h-g36phighDuplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
- GHSA-vfm7-4h43-gp6mmediumDuplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service
- GHSA-rg7q-4223-phjwhighDuplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Dat
- GHSA-xppm-jmw6-fhmflowDuplicate Advisory: Cross-site scripting via slot content in Nuxt's head components
- GHSA-5w6g-rc45-wvv9criticalDuplicate Advisory: Flowise OverrideConfig security vulnerability
- GHSA-6v7p-g79w-8964highMessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
- GHSA-6vxv-wg6j-5qwphighGogs: XSS in .ipynb files renderer due to outdated notebookjs
- CVE-2026-55828mediumCVE-2026-55828 updated by NVD
- GHSA-wjv4-x9w8-wm3hlowNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
- GHSA-5739-39v2-5754mediumPHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marv
- CVE-2026-57496criticalnetlicensing-mcp: REST Path Traversal Bypasses Token Redaction
- GHSA-7cx2-g3h9-382phighCrawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
- GHSA-vg9f-q4xh-62r4lowDuplicate Advisory: utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
- GHSA-chqm-wxm2-w73wmediumDuplicate Advisory: OpenClaw: Mattermost handlers could fall open when channel type was missing
- GHSA-c85p-9pvr-f7f5mediumDuplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state
- GHSA-gwcq-453v-2frrhighDuplicate Advisory: OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
- GHSA-p68j-q8j9-jwf5mediumDuplicate Advisory: OpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
- GHSA-ffhm-8fwq-7q27highDuplicate Advisory: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
- GHSA-r27j-fxmq-rg2qhighDuplicate Advisory: OpenClaw: QQBot streaming command could mutate config without explicit allowFrom
- GHSA-3qg8-hq7j-jj33highDuplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
- GHSA-35c7-4r45-9gv3highDuplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
- GHSA-g7r4-m6w7-qqqrlowesbuild allows arbitrary file read when running the development server on Windows
- GHSA-g53w-w6mj-hrppcriticalMCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-k
- GHSA-j7h9-2jh7-g967highmcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening
- GHSA-qcxq-75wr-5cm8highldap3_proto has LDAP Filter stack exhaustion
- GHSA-248h-974q-xrc2mediumaxonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verificatio
- GHSA-89gg-p5r5-q6r4highMONAI: Unsafe functions lead to pickle deserialization rce
- CVE-2026-73426mediumCVE-2026-73426 updated by NVD
- GHSA-m7j5-r2p5-c39rmediumpicklescan vulnerable to arbitrary file create using logging.FileHandler
- GHSA-2cgv-28vr-rv6jhighlibcrux incorrectly calculates on aarch64
- GHSA-99pg-hqvx-r4gfcriticalFlowise has an Arbitrary File Read
- GHSA-5wjw-h8x5-v65mmediumDuplicate Advisory: Wildfly HAL Console Cross-Site Scripting
- GHSA-p7mv-53f2-4cwjhighCometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
- GHSA-rc7v-65v6-m2v3criticalWithdrawn Advisory: go-mysql affected by go.uuid's Predictable UUID Identifiers
- GHSA-2gh6-wc3m-g37fcriticalhermes-management is vulnerable to RCE due to Apache commons-jxpath
- GHSA-3qwc-47jf-5rf7mediumeth-abi is vulnerable to recursive DoS
- GHSA-hj8m-9fhf-v7jpcriticalfief-server Server-Side Template Injection vulnerability
- GHSA-cpmr-mw4j-99r7highNginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
- GHSA-36jr-mh4h-2g58highd3-color vulnerable to ReDoS
- CVE-2026-6722criticalCVE-2026-6722 updated by NVD
- CVE-2026-6735highCVE-2026-6735 updated by NVD
- CVE-2026-7260mediumCVE-2026-7260 updated by NVD
- CVE-2026-7259lowCVE-2026-7259 updated by NVD
- CVE-2026-7258mediumCVE-2026-7258 updated by NVD
- CVE-2026-7261mediumCVE-2026-7261 updated by NVD
- CVE-2026-7262lowCVE-2026-7262 updated by NVD
- CVE-2026-7263mediumCVE-2026-7263 updated by NVD
- CVE-2026-9076highCVE-2026-9076 updated by NVD
- CVE-2026-7568mediumCVE-2026-7568 updated by NVD
- CVE-2026-75803criticalCVE-2026-75803 updated by NVD
- CVE-2026-6104mediumCVE-2026-6104 updated by NVD
- CVE-2026-63075highCVE-2026-63075 updated by NVD
- CVE-2026-63074mediumCVE-2026-63074 updated by NVD
- CVE-2026-63073criticalCVE-2026-63073 updated by NVD
- CVE-2026-63072highCVE-2026-63072 updated by NVD
- CVE-2026-63076highCVE-2026-63076 updated by NVD
- CVE-2026-7383highCVE-2026-7383 updated by NVD
- CVE-2026-54874highCVE-2026-54874 updated by NVD
- CVE-2026-58043highCVE-2026-58043 updated by NVD
- CVE-2026-56850mediumCVE-2026-56850 updated by NVD
- CVE-2026-56847mediumCVE-2026-56847 updated by NVD
- CVE-2026-48619highCVE-2026-48619 updated by NVD
- CVE-2026-49261criticalCVE-2026-49261 updated by NVD
- CVE-2026-48937highCVE-2026-48937 updated by NVD
- CVE-2026-48931lowCVE-2026-48931 updated by NVD
- CVE-2026-48933highCVE-2026-48933 updated by NVD
- CVE-2026-48934mediumCVE-2026-48934 updated by NVD
- CVE-2026-48935lowCVE-2026-48935 updated by NVD
- CVE-2026-48930criticalCVE-2026-48930 updated by NVD
- CVE-2026-48165highCVE-2026-48165 updated by NVD
- CVE-2026-48163highCVE-2026-48163 updated by NVD
- CVE-2026-48615highCVE-2026-48615 updated by NVD
- CVE-2026-48928mediumCVE-2026-48928 updated by NVD
- CVE-2026-48617highCVE-2026-48617 updated by NVD
- CVE-2026-48618mediumCVE-2026-48618 updated by NVD
- CVE-2026-48936lowCVE-2026-48936 updated by NVD
- CVE-2023-22458mediumCVE-2023-22458 updated by NVD
- CVE-2023-22084mediumCVE-2023-22084 updated by NVD
- CVE-2022-1434mediumCVE-2022-1434 updated by NVD
- CVE-2022-24048highCVE-2022-24048 updated by NVD
- CVE-2022-24050highCVE-2022-24050 updated by NVD
- CVE-2022-24051highCVE-2022-24051 updated by NVD
- CVE-2022-24052highCVE-2022-24052 updated by NVD
- CVE-2022-24735lowCVE-2022-24735 updated by NVD
- CVE-2022-24736lowCVE-2022-24736 updated by NVD
- CVE-2022-4203mediumCVE-2022-4203 updated by NVD
- CVE-2022-24834highCVE-2022-24834 updated by NVD
- CVE-2022-1473highCVE-2022-1473 updated by NVD
- CVE-2022-2068highCVE-2022-2068 updated by NVD
- CVE-2023-25155mediumCVE-2023-25155 updated by NVD
- CVE-2022-2097mediumCVE-2022-2097 updated by NVD
- CVE-2022-31621mediumCVE-2022-31621 updated by NVD
- CVE-2022-31622mediumCVE-2022-31622 updated by NVD
- CVE-2022-31623mediumCVE-2022-31623 updated by NVD
- CVE-2022-31624mediumCVE-2022-31624 updated by NVD
- CVE-2022-31625highCVE-2022-31625 updated by NVD
- CVE-2022-31626highCVE-2022-31626 updated by NVD
- CVE-2022-31627highCVE-2022-31627 updated by NVD
- CVE-2022-31628lowCVE-2022-31628 updated by NVD
- CVE-2022-31629mediumCVE-2022-31629 updated by NVD
- CVE-2022-31630mediumCVE-2022-31630 updated by NVD
- CVE-2022-31631criticalCVE-2022-31631 updated by NVD
- CVE-2023-3446mediumCVE-2023-3446 updated by NVD
- CVE-2022-21427mediumCVE-2022-21427 updated by NVD
- CVE-2022-32081highCVE-2022-32081 updated by NVD
- CVE-2022-32082highCVE-2022-32082 updated by NVD
- CVE-2022-32083highCVE-2022-32083 updated by NVD
- CVE-2022-32084highCVE-2022-32084 updated by NVD
- CVE-2022-32085highCVE-2022-32085 updated by NVD
- CVE-2022-32086highCVE-2022-32086 updated by NVD
- CVE-2022-32087highCVE-2022-32087 updated by NVD
- CVE-2022-32088highCVE-2022-32088 updated by NVD
- CVE-2022-32089highCVE-2022-32089 updated by NVD
- CVE-2022-32091highCVE-2022-32091 updated by NVD