Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,787 advisories

Loading
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials Moderate
CVE-2026-59222 was published for open-webui (pip) Jul 24, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, and grumpinout1 JorianWoltjer JorianWoltjer
grumpinout1 grumpinout1
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
Classic298 Credited to Classic298
jagstack Credited to jagstack and Classic298 Classic298 Classic298
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
sfwani Credited to sfwani, DavidCarliez, and Classic298 DavidCarliez DavidCarliez
Classic298 Classic298
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout High
CVE-2026-59219 was published for open-webui (pip) Jul 24, 2026
huslayer826 Credited to huslayer826 and Classic298 Classic298 Classic298
sfwani Credited to sfwani and Classic298 Classic298 Classic298
jagstack Credited to jagstack and Classic298 Classic298 Classic298
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config Moderate
CVE-2026-59220 was published for open-webui (pip) Jul 24, 2026
Vlad-WKG Credited to Vlad-WKG and Classic298 Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Account enumeration via observable login timing discrepancy Moderate
CVE-2026-59218 was published for open-webui (pip) Jul 24, 2026
dievus Credited to dievus and Classic298 Classic298 Classic298
Open WebUI: Stored web worker XSS via Pyodide High
CVE-2026-59214 was published for open-webui (pip) Jul 24, 2026
gg0h Credited to gg0h and Classic298 Classic298 Classic298
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution High
CVE-2026-55607 was published for @anthropic-ai/claude-code (npm) Jul 24, 2026
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion High
GHSA-v74w-7mr3-4qg3 was published for io.netty:netty-codec-xml (Maven) Jul 24, 2026
violetagg Credited to violetagg
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names Moderate
GHSA-mfg7-5gfp-c4w3 was published for io.netty:netty-codec-dns (Maven) Jul 24, 2026
violetagg Credited to violetagg
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag Moderate
GHSA-gcjh-h69q-9w9g was published for github.com/google/cel-go (Go) Jul 24, 2026
anaximand3r Credited to anaximand3r and doyensec-mohamed doyensec-mohamed doyensec-mohamed
js-yaml: Exponential parsing time in flow collections leads to denial of service High
GHSA-pm4m-ph32-ghv5 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS) Moderate
GHSA-g9hv-x236-4qp3 was published for russh (Rust) Jul 24, 2026
Zhaodl1 Credited to Zhaodl1
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
GHSA-cqjc-rmpq-xprq was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB) Moderate
GHSA-5xvq-cp9x-6p6r was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl and Zhaodl1 Zhaodl1 Zhaodl1
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response High
GHSA-qwww-vcr4-c8h2 was published for react-router (npm) Jul 24, 2026
radityahack Credited to radityahack
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths Moderate
CVE-2026-7120 was published for @fastify/static (npm) Jul 24, 2026
yuki-matsuhashi Credited to yuki-matsuhashi, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API