An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

35,004

Total Advisories

3,109

With Dependabot PRs

4,557

Critical Severity

12,256

High Severity

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
GHSA-464c-974j-9xm6 LOW 4 days ago
## Summary The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and ...
go maven npm +2 more
No PRs yet
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
GHSA-h22j-f9xw-xjjm CVE-2026-62946 MODERATE 4 days ago
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
nuget
No PRs yet
ImageMagick: Heap Buffer Over-Write in fx operation
GHSA-422r-8c97-xcg4 CVE-2026-62363 MODERATE 4 days ago
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
nuget
No PRs yet
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
GHSA-f5m7-cqgw-8hm7 CVE-2026-62343 MODERATE 4 days ago
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
nuget
No PRs yet
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
GHSA-p5rm-jg5c-8c77 MODERATE 4 days ago
### Impact Kiota generates AI plugin manifests from an OpenAPI description. When the description contains an `x-ai-capabilities` response semantic...
nuget
No PRs yet
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
GHSA-4vv7-jj25-4gh6 CVE-2026-59866 HIGH 4 days ago
### Summary Microsoft Kiota emitted the `x-ms-kiota-info` extension's `clientClassName` or `clientNamespaceName` value **raw**, with no identifier...
nuget
No PRs yet
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
GHSA-hq9q-27g5-qwpj CVE-2026-59865 CRITICAL 4 days ago
### Summary `kiota info` — the command developers run to learn which packages to install after generating a client — read the `x-ms-kiota-info` ex...
nuget
No PRs yet
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
GHSA-4rj6-vrwv-wr8m CVE-2026-59863 HIGH 4 days ago
### Summary Microsoft Kiota honors a poisoned `.kiota/workspace.json` — the workspace configuration that Kiota's documented team workflow has deve...
nuget
No PRs yet
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
GHSA-rg4h-fpcp-2qm8 CVE-2026-59867 HIGH 4 days ago
## Summary Microsoft Kiota resolved OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree pa...
nuget
No PRs yet
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
GHSA-4jwf-m4wg-8p66 CVE-2026-59864 CRITICAL 4 days ago
### Summary `kiota plugin add` / `kiota plugin generate` (with `-t APIPlugin`) emits an attacker-controlled `static_template.file` path from the A...
nuget
No PRs yet
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
GHSA-jqwh-526h-c92j CVE-2026-59859 HIGH 4 days ago
# Impact The Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI...
nuget
No PRs yet
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
GHSA-7f3j-j7jj-r3vr CVE-2026-59862 HIGH 4 days ago
Code Generation Literal Injection in Kiota Python Generator Leads to Arbitrary Code Execution at Import Time. The Kiota Python code generator is v...
nuget
No PRs yet
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
GHSA-xg2h-5xr2-29jw CVE-2026-59861 HIGH 4 days ago
Code Generation Literal Injection in Kiota Ruby Generator Leads to Arbitrary Code Execution # Impact The Kiota Ruby code generator is vulnerable ...
nuget
No PRs yet
ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
GHSA-76q6-2p6h-xjqr LOW 4 days ago
Running an X11 import with a crafted window title can result in a heap buffer over-write.
nuget
No PRs yet
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-3hrf-2gc2-mx32 CVE-2026-59860 HIGH 4 days ago
### Summary Kiota versions **prior to 1.32.3** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink ...
nuget
No PRs yet
ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
GHSA-h5r4-w88w-7ccr LOW 4 days ago
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
nuget
No PRs yet
ImageMagick: Memory Leak in ICON decoder when allocation fails
GHSA-h58x-r7f7-rh84 LOW 4 days ago
A memory leak will occur in the ICON decoder when an allocation fails.
nuget
No PRs yet
ImageMagick: Memory leak in VIFF encoder when allocation fails
GHSA-m596-67p7-69wh LOW 4 days ago
When an allocation fails in the VIFF encoder a memory leak will occus.
nuget
No PRs yet
ImageMagick: Memory Leak in MIFF encoder when allocaton fails
GHSA-r628-69v2-2f9c LOW 4 days ago
A memory leak will occur in the MIFF encoder when an allocation fails.
nuget
No PRs yet
ImageMagick: Memory Leak in YUV decoder when opening of blob fails
GHSA-h7f2-f9cc-h2gv LOW 4 days ago
A memory leak will occur when a blob cannot be opened in the YUV decoder.
nuget
No PRs yet
ImageMagick: Memory Leak in TIFF encoder when an allocation fails
GHSA-jfq9-q63x-rc63 LOW 4 days ago
When an allocation fails in the TIFF encoder a small memory leak will occur.
nuget
No PRs yet
ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
GHSA-99w9-hv66-rfv7 LOW 4 days ago
When a blob can not be opened a memory leak will occur when encoding a JNG file.
nuget
No PRs yet
ImageMagick: Memory Leak in hough lines operation when an operation fails
GHSA-j8rh-v2r8-v94x LOW 4 days ago
When a specific operation fails in the hough lines operation a small memory leak will occur.
nuget
No PRs yet
ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
GHSA-7c7m-fpjw-gwcq LOW 4 days ago
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
nuget
No PRs yet
ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
GHSA-6vxp-gfwf-hcr9 LOW 4 days ago
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
nuget
No PRs yet
ImageMagick: Information Disclosure when printing profiles with debug enabled
GHSA-hwf3-r46v-5ggx LOW 4 days ago
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
nuget
No PRs yet
ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
GHSA-qvxh-prvr-85w2 LOW 4 days ago
When a memory allocation fails inside the FormatMagickCaption method a dangling pointer still points to the freed memory.
nuget
No PRs yet
ImageMagick: Use-After-Free when freetype initialization fails
GHSA-6jwg-7q3p-5fqm LOW 4 days ago
When the freetype initialization fails the method does not exit and uses memory that was freed.
nuget
No PRs yet
ImageMagick: Policy Bypass in script operation due to missing checks
GHSA-vghg-5jrg-2398 LOW 4 days ago
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
nuget
No PRs yet
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
GHSA-v3j6-27vc-7pw2 LOW 4 days ago
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
nuget
No PRs yet
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
GHSA-qh5g-q395-cx4j LOW 4 days ago
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
nuget
No PRs yet
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-hc76-7mpc-qjqh MODERATE 4 days ago
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
nuget
No PRs yet
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-56m6-8q75-f2rw MODERATE 4 days ago
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
nuget
No PRs yet
ImageMagick: Policy Bypass possible with matrix-backed operations
GHSA-rvhp-75f6-9jqh LOW 4 days ago
Matrix bases operations like `-canny` are missing a check for allowed memory allocation that could result allocating more memory than allowed.
nuget
No PRs yet
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-82mp-vp5c-9pf7 CVE-2026-55628 MODERATE 4 days ago
The `-concatenate` operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
nuget
No PRs yet
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
GHSA-c4v7-w88g-m6c4 CVE-2026-55597 MODERATE 4 days ago
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
nuget
No PRs yet
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-qhmf-7fc4-8q3h CVE-2026-55595 MODERATE 4 days ago
When providing invalid arguments to the connected-components option an infinite loop will occur.
nuget
No PRs yet
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
GHSA-mx48-2qq3-23hf CVE-2026-55594 MODERATE 4 days ago
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
nuget
No PRs yet
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-ff5c-8x9r-8qcw CVE-2026-55510 MODERATE 4 days ago
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
nuget
No PRs yet
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
GHSA-8g53-9m3c-69xg CVE-2026-53467 MODERATE 5 days ago
In the MNG decoder there is a possible heap information disclosure because part of the pixels are left unchanged.
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
GHSA-j8gr-8fp3-5q5h CVE-2026-56170 HIGH 7 days ago
# Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability ## Executive summary Microsoft is releasing this security adv...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
GHSA-55jh-fwmh-39m4 CVE-2026-50526 HIGH 7 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SDK (Microsoft.NET.Build.C...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
GHSA-8prm-248r-h957 CVE-2026-47300 HIGH 7 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authenti...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
GHSA-2p3q-h3hg-jcqq CVE-2026-47303 HIGH 7 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authenti...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
GHSA-mmjf-rqrv-855v CVE-2026-50527 HIGH 7 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
GHSA-2969-4q4w-w5h3 CVE-2026-50650 HIGH 7 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
GHSA-wp74-jgxh-gv4q CVE-2026-50651 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Ht...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
GHSA-74jp-vm22-8q8x CVE-2026-50659 MODERATE 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Ma...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
GHSA-8q5v-6pqq-x66h CVE-2026-50525 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Sec...
nuget
No PRs yet
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-qvw7-jm5c-6hqw CVE-2026-50528 HIGH 8 days ago
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Securi...
nuget
No PRs yet