GitHub Security Advisories

GitHub Security Advisories (GHSA) are authoritative notices for vulnerable open-source packages and ecosystems (for example npm, PyPI, or Maven), usually with a linked CVE. Use the search box to find a GHSA or CVE, narrow by ecosystem or severity, or match phrases in the summary.

Showing 2140 of 6836 advisories
«« First « Prev Page 2 / 342 Next »
GHSA CVE Severity Type Summary Published
GHSA-8qw8-rq86-9pc2 CVE-2026-27771 high reviewed Gitea has insufficient permission checks for Composer package source links 2026-07-17 19:04:37 UTC
GHSA-rjwr-m7qx-3fjr low reviewed oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code 2026-07-17 18:50:17 UTC
GHSA-xrh4-q49w-whmw CVE-2026-9588 high unreviewed A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ... 2026-07-17 18:31:27 UTC
GHSA-m32j-v93f-gfgc CVE-2026-9586 critical unreviewed An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ... 2026-07-17 18:31:27 UTC
GHSA-34c9-mcf5-3rp3 CVE-2026-9585 high unreviewed An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox... 2026-07-17 18:31:27 UTC
GHSA-25gv-rxp9-h9pc CVE-2026-9587 high unreviewed An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 ... 2026-07-17 18:31:27 UTC
GHSA-cfq8-274p-7h5p CVE-2026-12715 high unreviewed Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google... 2026-07-17 18:31:24 UTC
GHSA-cwxq-rc9x-2jvv CVE-2026-54247 medium reviewed Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS 2026-07-17 18:14:08 UTC
GHSA-mwgc-xrww-2crj CVE-2026-13410 high unreviewed Dancer::Plugin::Auth::Google versions through 0.07 for Perl have TLS verification disabled. The... 2026-07-17 15:32:28 UTC
GHSA-gf3x-ww5j-mxxm CVE-2026-16008 low unreviewed A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This... 2026-07-17 12:31:29 UTC
GHSA-wvmp-6r4v-j6cv CVE-2026-52724 medium reviewed kuma-dp connects to control plane without verifying TLS certificate when no CA is configured 2026-07-16 20:09:12 UTC
GHSA-wpcj-rmv4-86qg CVE-2026-52832 medium reviewed Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container 2026-07-16 19:47:17 UTC
GHSA-3v79-m2cg-89ww CVE-2026-52833 high reviewed Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE 2026-07-16 19:40:53 UTC
GHSA-22xc-xg2r-9j7v CVE-2026-53714 high reviewed Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode 2026-07-16 19:32:23 UTC
GHSA-wcrf-9vrr-854f CVE-2026-53713 critical reviewed Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure 2026-07-16 19:23:38 UTC
GHSA-8fv2-88gg-hm7q CVE-2026-53715 medium reviewed Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock 2026-07-16 19:21:15 UTC
GHSA-h7pq-86h8-rp5x CVE-2026-53717 medium reviewed Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header 2026-07-16 19:20:05 UTC
GHSA-m2v6-2jmh-4c68 CVE-2026-53719 medium reviewed Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization 2026-07-16 19:19:17 UTC
GHSA-cxpq-8v7q-cg56 CVE-2026-53716 medium reviewed Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit 2026-07-16 19:18:08 UTC
GHSA-fcrp-7gc2-93g7 CVE-2026-53718 medium reviewed Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass 2026-07-16 19:14:50 UTC
«« First « Prev Page 2 / 342 Next »
cvelogic Threat Intelligence