Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,374 advisories

Loading
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks Critical
CVE-2026-85734 was published for lightrag-hku (pip) Sep 22, 2026
MaramHarsha Credited to MaramHarsha
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function Moderate
CVE-2026-85725 was published for lightrag-hku (pip) Sep 22, 2026
MaramHarsha Credited to MaramHarsha
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses Moderate
CVE-2026-85709 was published for lightrag-hku (pip) Sep 22, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
pirate077000 Credited to pirate077000
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text Moderate
CVE-2026-83801 was published for nautobot (pip) Sep 22, 2026
pirate077000 Credited to pirate077000
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation Moderate
CVE-2026-77528 was published for autobahn (pip) Sep 22, 2026
hibrian827 Credited to hibrian827
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() High
CVE-2026-77258 was published for mcp-atlassian (pip) Sep 22, 2026
sondt99 Credited to sondt99
Yunkaiwjs Credited to Yunkaiwjs
junbyjun1238 Credited to junbyjun1238
crazydude123 Credited to crazydude123
MCP Atlassian: SSRF Protection Bypass High
CVE-2026-77274 was published for mcp-atlassian (pip) Sep 22, 2026
RacerZ-fighting Credited to RacerZ-fighting
b-hermes Credited to b-hermes
mcp-atlassian has an incomplete SSRF remediation High
CVE-2026-77267 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler Moderate
CVE-2026-77272 was published for mcp-atlassian (pip) Sep 22, 2026
offset Credited to offset
romain-deperne Credited to romain-deperne
MCP Atlassian: Insecure File Permissions on OAuth Token Storage Moderate
CVE-2026-77268 was published for mcp-atlassian (pip) Sep 22, 2026
offset Credited to offset
rushitgit Credited to rushitgit
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches High
CVE-2026-77261 was published for mcp-atlassian (pip) Sep 22, 2026
hewei-gikaku Credited to hewei-gikaku
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools Moderate
CVE-2026-77270 was published for mcp-atlassian (pip) Sep 22, 2026
offset Credited to offset
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow Moderate
CVE-2026-77265 was published for mcp-atlassian (pip) Sep 22, 2026
offset Credited to offset
hewei-gikaku Credited to hewei-gikaku
diemoeve Credited to diemoeve
ProTip! Advisories are also available from the GraphQL API