GitHub Advisory Database · GitHub

github.com

Tin mới

GitHub CopilotWrite better code with AI

GitHub Copilot appDirect agents from issue to merge

ActionsAutomate any workflow

CodespacesInstant dev environments

IssuesPlan and track work

Code ReviewManage code changes

Code QualityEnforce quality at merge

GitHub Advanced SecurityFind and fix vulnerabilities

Code securitySecure your code as you build

Secret protectionStop leaks before they start

View all use cases

Financial services

View all industries

Software Development

GitHub SponsorsFund open source developers

Copilot for BusinessEnterprise-grade AI features

Premium SupportEnterprise-grade 24/7 support

About GitHub Advisory Database

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

@openhop/server: Path Traversal in Flow ID File Operations

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

Joker linter executed project-local .jokerd/linter.* files during linting

Komari: Management Interface CSRF

@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

webhookd: Unrestricted HTTP Header to Shell Variable Injection

GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

smol-toml: Denial of Service via malformed TOML documents

weasyprint Has Server-Side Request Forgery (SSRF)

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

decidim-elections: Election question titles allow stored script execution

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: Self-XSS in External Service Creation

gix-sec safe.directory protections absent for elevated administrators

Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability