Thanks to visit codestin.com
Credit goes to github.com

Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

35,538 advisories

Loading
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
miauzxw Credited to miauzxw and geo-chen geo-chen geo-chen
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover Critical
CVE-2026-59151 was published for prowler-cloud (pip) Sep 11, 2026
EQSTLab Credited to EQSTLab, AdriiiPRodri, jfagoagas, and josema-xyz AdriiiPRodri AdriiiPRodri
jfagoagas jfagoagas josema-xyz josema-xyz
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider Moderate
CVE-2026-56665 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, IAM-marco, livio-a, and Punisher100 IAM-marco IAM-marco
livio-a livio-a Punisher100 Punisher100
Shopper: Missing authorization on product removal actions in CollectionProducts component High
CVE-2026-56825 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph) Moderate
CVE-2026-56830 was published for shopper/framework (Composer) Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component High
CVE-2026-56829 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: privilege escalation via improper Livewire admin component authorization High
CVE-2026-56828 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopping privilege escalation through missing authorization in Settings components Moderate
CVE-2026-56826 was published for shopper/framework (Composer) Sep 11, 2026
baradika Credited to baradika
Shopper: Negative discount values accepted and propagated through order calculation pipeline Moderate
CVE-2026-56831 was published for shopper/framework (Composer) Sep 11, 2026
Fr6ey Credited to Fr6ey
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror) High
CVE-2026-11745 was published for com.linecorp.centraldogma:centraldogma-server-mirror-git (Maven) Sep 11, 2026
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover Critical
CVE-2026-11746 was published for com.linecorp.centraldogma:centraldogma-server (Maven) Sep 11, 2026
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion Moderate
CVE-2026-11748 was published for com.linecorp.centraldogma:centraldogma-server-auth-shiro (Maven) Sep 11, 2026
designcomputer Credited to designcomputer
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange Moderate
CVE-2026-88006 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization High
CVE-2026-88008 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ihopenre-eng Credited to ihopenre-eng
Traefik entrypoint header-name sanitization bypassed via request trailers High
CVE-2026-88004 was published for github.com/traefik/traefik/v3 (Go) Sep 10, 2026
bipol4r Credited to bipol4r
Traefik HTTP/3 Backend NTLM Connection Reuse Critical
CVE-2026-88007 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
OneZ3r0 Credited to OneZ3r0
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace Moderate
CVE-2026-88014 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
ProTip! Advisories are also available from the GraphQL API