An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

34,981

Total Advisories

3,105

With Dependabot PRs

4,555

Critical Severity

12,244

High Severity

Unspecified security issues.
CPANSA-MySQL-Admin-1-1
Unspecified security issues.
cpan
No PRs yet
BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
EEF-CVE-2026-54890 GHSA-54pw-5645-jh86 CVE-2026-54890 HIGH about 3 hours ago
## Summary Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows For...
No PRs yet
Denial of service via exponential certificate policy tree growth in path validation
EEF-CVE-2026-59251 GHSA-622p-qfh6-c352 CVE-2026-59251 HIGH about 3 hours ago
## Summary Allocation of resources without limits in Erlang/OTP public\_key certificate path validation allows a remote unauthenticated attacker t...
No PRs yet
Megaco flex scanner buffer overflow via oversized property parm name
EEF-CVE-2026-59250 GHSA-7xgh-gmgf-q2g7 CVE-2026-59250 HIGH about 3 hours ago
## Summary Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's...
No PRs yet
TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication
EEF-CVE-2026-55953 GHSA-c6cw-pr89-w882 CVE-2026-55953 CRITICAL about 3 hours ago
## Summary The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello wa...
No PRs yet
Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder
EEF-CVE-2026-55737 GHSA-446w-268v-9462 CVE-2026-55737 MEDIUM about 3 hours ago
## Summary Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafte...
No PRs yet
Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass
EEF-CVE-2026-47078 GHSA-rf72-wp7h-jg3x CVE-2026-47078 MEDIUM about 3 hours ago
## Summary Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory ...
No PRs yet
epmd permanent DoS via EMFILE on accept(2) in erts
EEF-CVE-2026-42792 GHSA-h6f3-hx58-xhj6 CVE-2026-42792 MEDIUM about 3 hours ago
## Summary Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to perman...
No PRs yet
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
EEF-CVE-2026-58227 GHSA-r5jr-mq46-vmhw CVE-2026-58227 HIGH about 4 hours ago
## Summary The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS han...
No PRs yet
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-6vch-q96h-7gc3 HIGH 3 days ago
### Impact _What kind of vulnerability is it? Who is impacted?_ A network attacker who can reach an etcd TLS listener can open many TCP connection...
go
No PRs yet
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-8q49-2h5h-434x MODERATE 3 days ago
## Summary The OpenAPI adapter's spec-change **poller** (`OpenApiSpecPoller`) re-fetched the configured spec `url` on a timer using a raw global `...
npm
No PRs yet
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA-jpcw-4wr7-c3vq MODERATE 3 days ago
| Field | Value | |---|---| | Ecosystem | Go | | Package | `github.com/getkin/kin-openapi` | | Affected versions | `<= 0.143.0` (introduced in `v0....
go
No PRs yet
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
GHSA-j6g5-3hh3-pgw8 CVE-2026-16796 HIGH 3 days ago
### Summary The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client th...
pypi
No PRs yet
etcd: Watch API authorization bypass via open-ended range requests
GHSA-xg4h-6gfc-h4m8 HIGH 3 days ago
### Impact _What kind of vulnerability is it? Who is impacted?_ A user granted READ permission on a single, exact key can use the Watch gRPC API w...
go
No PRs yet
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx CVE-2026-16756 HIGH 3 days ago
## Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, pow...
cargo
No PRs yet
libp2p: yamux connection DoS via oversized data frame
GHSA-hmj8-5xmh-5573 HIGH 3 days ago
### Summary The yamux stream multiplexer in py-libp2p does not validate incoming DATA frame lengths against the receive window before reading the f...
pypi
No PRs yet
Quasar: Prototype pollution in the extend() utility
GHSA-3r53-75j5-3g7j MODERATE 3 days ago
### Summary `quasar@2.20.1`, the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the publ...
npm
No PRs yet
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-6xj8-qv9j-xcjq HIGH 3 days ago
### Summary Oh My Posh re-renders the resolved path string, which contains the raw folder names taken from the filesystem, through the Go `text/tem...
go
No PRs yet
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-fwjx-9p69-h25h MODERATE 3 days ago
### Summary Oh My Posh renders dynamic, potentially attacker-controlled strings (the current directory name, Git commit metadata, environment varia...
go
No PRs yet
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA-fp43-vj7g-pg92 HIGH 3 days ago
## 1. Forged combined-resource IDs `CombinedResourceInfo` accepts a path-derived ID without an authenticity check, inflates it without an output li...
maven
No PRs yet
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-gm3r-q2wp-hw87 HIGH 3 days ago
### Impact This impacts users of Shescape that have flag protection enabled, which is on by default, regardless of the API being used. An attacke...
npm
No PRs yet
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-q53c-4prm-w95q MODERATE 3 days ago
### Impact This impacts users of Shescape on Unix systems that explicitly configure `shell` to Dash, or `true` when the default shell is Dash, usi...
npm
No PRs yet
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA-w4hw-qcx7-56pr CRITICAL 3 days ago
### Impact This impacts users of Shescape on Windows that explicitly configure `shell` to CMD, or `true` with the default shell being CMD, using t...
npm
No PRs yet
Shescape: Path disclosure on Unix with Zsh
GHSA-6v4m-fw66-8r4x MODERATE 3 days ago
### Impact This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using...
npm
No PRs yet
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-29w2-fq35-v728 CVE-2026-16584 HIGH 3 days ago
## Summary The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services an...
pypi
No PRs yet
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA-86cx-wwf4-phq4 MODERATE 3 days ago
### Summary An authorization bypass vulnerability exists in the file sharing mechanism of `Openlist`. Due to a flawed, non-separator-aware path val...
go
No PRs yet
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA-p6ph-3jx2-3337 MODERATE 3 days ago
### Summary An authorization bypass and information disclosure vulnerability exists in the search API of `Openlist`. Due to a non-separator-aware p...
go
No PRs yet
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-95cv-r8x4-vh75 HIGH 3 days ago
### Summary The `/api/fs/batch_rename` handler validates and authorizes only the requested source directory. It rejects path separators in `new_na...
go
No PRs yet
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-7ppr-r889-mcf2 HIGH 3 days ago
## Summary `http4s-blaze-server` aggregates the fragments of an incoming WebSocket message with no limit on total size or fragment count. A client...
maven
No PRs yet
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA-46q4-43ph-c6fr HIGH 3 days ago
### Summary blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Because trailer fields are attacker-controlled, a...
maven
No PRs yet
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-mhvj-jhpq-885v HIGH 3 days ago
### Summary Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`http/src/main/java/org/http4s/blaze/http/parser/...
maven
No PRs yet
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
GHSA-cmwh-g2h8-c222 HIGH 3 days ago
## Preface Poweradmin maps OIDC identities into local users through `oidc_user_links.oidc_subject` plus `provider_id`. In the MySQL schema, the OI...
packagist
No PRs yet
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
GHSA-rm67-g9ch-vxff HIGH 3 days ago
## Affected software - Product: Poweradmin (web front-end for PowerDNS) - Version tested: master, commit 7f28c3a97 (also reachable in the 4.x rele...
packagist
No PRs yet
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
GHSA-h4hf-v6w5-897x HIGH 3 days ago
### Summary The REST API user-update endpoint (`PUT/PATCH /api/v2/users/{id}` and the V1 equivalent) does not enforce two authorization rules that...
packagist
No PRs yet
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
GHSA-f25v-x6vr-962g CRITICAL 3 days ago
## Summary The forced password-change flow, triggered when the stored password is still the default (`admin`), does not verify that the password s...
packagist
No PRs yet
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-mh99-v99m-4gvg CVE-2026-14257 HIGH 3 days ago
### Summary `expand()` bounds the *number* of results it produces (the `max` option, `100_000` by default) but not their *length*. By chaining man...
npm
No PRs yet
swift-nio-http2: Missing CR/LF/NUL validation in header values
GHSA-q3g2-m552-3r9c CVE-2026-64785 MODERATE 3 days ago
## Summary SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1....
swift
No PRs yet
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
GHSA-vh45-f885-3848 CRITICAL 3 days ago
## Summary `sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20) generates SM2 private keys and signing ephemeral scalars ...
npm
No PRs yet
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
GHSA-v6w6-358x-2433 MODERATE 3 days ago
## Summary Cloudreve exposes two admin node test endpoints under the `Admin.Read` OAuth scope. These endpoints accept attacker-controlled node def...
go
No PRs yet
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GHSA-47w6-gwp4-w6vc HIGH 3 days ago
### Impact Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes. Worst they could do i...
pypi
No PRs yet
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
GHSA-2625-rw7m-5q5x LOW 3 days ago
## Summary `hubuum_client` diagnostics can expose sensitive request, response, import/export, task, delivery, or server-provided data when applica...
cargo
No PRs yet
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-qqc3-94qv-7fw3 MODERATE 3 days ago
## Summary When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwe...
cargo
No PRs yet
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-f45q-w629-wr25 MODERATE 3 days ago
## Impact The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configur...
cargo
No PRs yet
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-26gq-p25f-99cp HIGH 3 days ago
## Summary An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the en...
go
No PRs yet
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-g5vv-q72c-7j78 HIGH 3 days ago
### Summary `@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the re...
npm
No PRs yet
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
GHSA-c534-2w9c-x7fm MODERATE 3 days ago
## Summary Kite versions 0.6.9 through 0.14.0 authorize Kubernetes proxy requests against the pod or service identified by the original route para...
go
No PRs yet
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
GHSA-p279-2cqp-84jg CRITICAL 3 days ago
### Summary When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler ve...
maven
No PRs yet
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-68r5-9hpg-7qw9 CRITICAL 3 days ago
The DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenIdentityPlatform OpenDJ through 5.1.1 dereferences attacker-supplied xsd:anyURI values server-...
maven
No PRs yet
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
GHSA-g3hq-hphg-8fhh HIGH 3 days ago
### Summary pheditor's terminal feature restricts callers to an allowlist of commands (`TERMINAL_COMMANDS`) and rejects shell metacharacters. The ...
packagist
No PRs yet
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-94p4-4cq8-9g67 HIGH 3 days ago
## Summary The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `R...
pypi
No PRs yet