Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

791 advisories

Loading
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies High
CVE-2026-84381 was published for httpcore2 (pip) Sep 8, 2026
maxisbey Credited to maxisbey
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default High
CVE-2026-84366 was published for scrapy (pip) Sep 2, 2026
syncrain Credited to syncrain
fg0x0 Credited to fg0x0
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55857 was published for org.mariadb.jdbc:mariadb-java-client (Maven) Aug 28, 2026
fg0x0 Credited to fg0x0
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials Moderate
CVE-2026-55854 was published for mariadb (npm) Aug 28, 2026
fg0x0 Credited to fg0x0
MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive... Critical Unreviewed
CVE-2026-69658 was published Aug 28, 2026
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and... High Unreviewed
CVE-2026-81691 was published Aug 27, 2026
ProTip! Advisories are also available from the GraphQL API