Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,374 advisories

Loading
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths High
CVE-2026-77257 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass High
CVE-2026-77243 was published for mcp-atlassian (pip) Sep 22, 2026
0xmagic0 Credited to 0xmagic0
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue High
CVE-2026-77255 was published for mcp-atlassian (pip) Sep 22, 2026
aurelienp-alt Credited to aurelienp-alt
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files High
CVE-2026-77253 was published for mcp-atlassian (pip) Sep 22, 2026
sondt99 Credited to sondt99
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path High
CVE-2026-77246 was published for mcp-atlassian (pip) Sep 22, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers Moderate
CVE-2026-65829 was published for MPXJ.Net (RubyGems) Sep 22, 2026
czTangt Credited to czTangt
MPXJ: XXE Vulnerability in MerlinReader High
CVE-2026-61570 was published for MPXJ.Net (RubyGems) Sep 22, 2026
dyingman1 Credited to dyingman1
wlc may disclose API tokens to project-configured URLs Low
CVE-2026-62364 was published for wlc (pip) Sep 22, 2026
nijel Credited to nijel, type5afe, and visionxstack type5afe type5afe
visionxstack visionxstack
OpenCVE: Server-Side Request Forgery (SSRF) in notifications Moderate
CVE-2026-62282 was published for opencve (pip) Sep 22, 2026
geo-chen Credited to geo-chen
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry High
CVE-2026-59991 was published for psd-tools (pip) Sep 22, 2026
joszamama Credited to joszamama
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass Critical
CVE-2026-59163 was published for mnemosyne-memory (pip) Sep 18, 2026
dplush Credited to dplush
Faze-up Credited to Faze-up
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing Critical
CVE-2026-63374 was published for anyio (pip) Sep 18, 2026
AnyIO process-pool workers can block indefinitely on undrained stderr Moderate
CVE-2026-64847 was published for anyio (pip) Sep 18, 2026
LMDeploy has an SSRF bypass High
GHSA-39wr-7q6h-cf68 was published for lmdeploy (pip) Sep 18, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and clzoom RacerZ-fighting RacerZ-fighting
clzoom clzoom
romain-deperne Credited to romain-deperne
Chenpinji Credited to Chenpinji, berkant-koc, beanduan22, Wernerina, AAtomical, kta1kri, professor-moody, and rollingWaves berkant-koc berkant-koc
beanduan22 beanduan22 Wernerina Wernerina AAtomical AAtomical kta1kri kta1kri professor-moody professor-moody rollingWaves rollingWaves
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns Moderate
CVE-2026-86000 was published for soupsieve (pip) Sep 17, 2026
kaimandalic Credited to kaimandalic
kaimandalic Credited to kaimandalic
djust: A template binding inherits a context safety grant it never earned (XSS) High
GHSA-xjw9-38cr-6372 was published for djust (pip) Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS) High
GHSA-9395-2g46-rj3f was published for djust (pip) Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values High
CVE-2026-86049 was published for jupyter_server (pip) Sep 17, 2026
DavidCarliez Credited to DavidCarliez, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation Moderate
CVE-2026-69147 was published for vllm (pip) Sep 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
ProTip! Advisories are also available from the GraphQL API