An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

35,093

Total Advisories

3,110

With Dependabot PRs

4,562

Critical Severity

12,297

High Severity

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
GHSA-q3fv-x8vg-qqm4 CVE-2026-54448 HIGH 16 days ago
## Summary When Trivy scans a Helm chart archive (`.tgz`), its custom tar unpacker reads each entry with `io.ReadAll(tr)` and no size limit. An at...
go
No PRs yet
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
GHSA-8559-gwj3-q37r CVE-2026-54087 HIGH 16 days ago
EasyAdmin's `FileField` and `ImageField` accept browser-executable file types by default (`FileField` applies no MIME/extension restrictions; `Imag...
packagist
No PRs yet
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
GHSA-pqg7-v6wh-3pfp HIGH 16 days ago
## Description The HTTP reverse proxy handler in tsdproxy does not strip the X-Forwarded-For (or X-Real-IP) header from incoming requests before c...
go
No PRs yet
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
GHSA-28xv-ph75-77wh CVE-2026-54335 LOW 16 days ago
### Impact The `_.merge(target, source)` utility exported by `@feathersjs/commons` recursively merges `source` into `target` by iterating `Object....
npm
No PRs yet
yutu: Arbitrary File Write via MCP `caption-download` Tool
GHSA-2c7f-fxww-6w6c CVE-2026-50158 HIGH 16 days ago
## Arbitrary File Write via MCP `caption-download` Tool ### Summary The `caption-download` MCP tool in yutu passes the caller-supplied `file` par...
go
No PRs yet
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
GHSA-ffq7-hh2j-r24p CVE-2026-50157 MODERATE 16 days ago
### Description Applications built with the Auth0 Symphony SDK, using the Authorizer security authenticator to protect HTTP routes may accept OAuth...
packagist
No PRs yet
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
GHSA-j6r7-6fhx-77wx CVE-2026-54052 CRITICAL 16 days ago
## Impact In multi-tenant HTTP deployments — where a single n8n-mcp server serves several tenants — the locally stored workflow version history (t...
npm
No PRs yet
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
GHSA-g7mm-9vx7-jm7h CVE-2026-50141 HIGH 16 days ago
### Impact A vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injec...
go
No PRs yet
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
GHSA-xrcf-6jh3-ggvx CVE-2026-50006 CRITICAL 16 days ago
## Summary Anyquery's `server` mode does not disable or restrict native SQLite disk manipulation commands. Unauthenticated attackers connecting to ...
go
No PRs yet
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
GHSA-xw9q-2mv6-9fr8 CVE-2026-50131 HIGH 16 days ago
### Summary Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime documen...
npm
No PRs yet
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion
GHSA-qw5r-ppcg-f8rj CVE-2026-50125 HIGH 16 days ago
## Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion ### Summary The MKP (Model Context Protocol f...
go
No PRs yet
Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
GHSA-42j2-w334-qxw7 CVE-2026-50018 MODERATE 16 days ago
### Summary: Remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or inte...
go
No PRs yet
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
GHSA-qrh4-p6v4-mrfg CVE-2026-50013 HIGH 16 days ago
### Summary: When Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization ...
go
No PRs yet
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
GHSA-jxr7-mqhw-9p98 CVE-2026-54250 MODERATE 16 days ago
#### Summary A path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with m...
go
No PRs yet
Wasmtime: Memory leak in C API with `externref` and `anyref` types
GHSA-vvp9-h8p2-xwfc CVE-2025-61670 LOW 16 days ago
### Impact Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. T...
cargo pypi
No PRs yet
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
GHSA-3x7p-v8hj-xh5m CVE-2026-45710 LOW 16 days ago
## Summary `WidgetVariante::renderVariantList` (`Core/Lib/Widget/WidgetVariante.php:298-330`) and `WidgetSubcuenta::renderSubaccountList` (`Core/L...
packagist
No PRs yet
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
GHSA-2p5x-4jr6-x5jg CVE-2026-45263 HIGH 16 days ago
## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A low-privilege user (`lowpriv`) created ...
packagist
No PRs yet
FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
GHSA-cv65-7cg8-r623 CVE-2026-45693 HIGH 16 days ago
### Summary The static file controllers in FacturaScripts decide whether a request is authorized by looking at the URL string instead of the canon...
packagist
No PRs yet
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
GHSA-5qmh-x653-g8qj CVE-2026-45262 CRITICAL 16 days ago
## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A scoped `ApiKey` with `fullaccess=0` and...
packagist
No PRs yet
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
GHSA-wmj8-9953-vff5 CVE-2026-44300 HIGH 16 days ago
## Summary OpenCost contains an unauthenticated file write vulnerability in the `/serviceKey` endpoint that allows remote attackers to overwrite ...
go
No PRs yet
Missing ID token claim validation in ueberauth_apple allows account takeover
EEF-CVE-2026-55954 GHSA-pxx8-68pc-p9mr CVE-2026-55954 CRITICAL 16 days ago
## Summary Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth\_apple allows account takeover via unvalidated ID token claims. ...
hex
No PRs yet
Zero-length HTTP/2 CONTINUATION frames bypass Mint's header-block byte-size cap and exhaust client memory
EEF-CVE-2026-59246 GHSA-8pf6-g464-h6h9 CVE-2026-59246 MEDIUM 16 days ago
## Summary Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on the client ...
hex
No PRs yet
Unbounded HTTP/1 response-header and chunked-trailer accumulation in Mint causes memory-exhaustion DoS
EEF-CVE-2026-58229 GHSA-qrfr-wh4c-3qhw CVE-2026-58229 HIGH 16 days ago
## Summary Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client ho...
hex
No PRs yet
Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access
GHSA-rw46-qg69-vg6h CVE-2026-52828 MODERATE 17 days ago
### Summary The `ExportController` web routes for creating and editing export templates are gated only by the class-level `create_export` permissi...
packagist
No PRs yet
Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP
GHSA-v8hx-4vx8-wc96 CVE-2026-52827 HIGH 17 days ago
### Summary Two-factor authentication (TOTP) can be fully bypassed for the REST API. The `KIMAI_SESSION` cookie returned in the response to the log...
packagist
No PRs yet
Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation
GHSA-2xgg-2x8h-8xw4 CVE-2026-52826 MODERATE 17 days ago
### Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the Web rate editing flows for projects, customers, and...
packagist
No PRs yet
Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility
GHSA-xv4r-4885-gwpg CVE-2026-52825 MODERATE 17 days ago
### Summary Kimai contains an authenticated improper authorization vulnerability in Team-related assignment APIs. A Teamlead who can edit their ow...
packagist
No PRs yet
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
GHSA-jr9p-4h4j-6c58 CVE-2026-52824 CRITICAL 17 days ago
### Summary The official Kimai Docker image ships with `APP_SECRET=change_this_to_something_unique` as the default environment variable. The Docke...
packagist
No PRs yet
Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes
GHSA-r8vr-m544-qh4h CVE-2026-52823 MODERATE 17 days ago
### Summary Kimai 2.56.0 contains authenticated cross-site request forgery issues in its timesheet state-changing API endpoints. The application r...
packagist
No PRs yet
Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation
GHSA-c6w6-57jj-62vh CVE-2026-52822 MODERATE 17 days ago
### Summary Kimai 2.56.0 contains an authenticated authorization bypass in the timesheet `restart` and `duplicate` workflows. After a user loses a...
packagist
No PRs yet
Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects
GHSA-3q6q-26vg-v97x CVE-2026-52821 MODERATE 17 days ago
### Summary Kimai 2.56.0 contains an authenticated improper authorization vulnerability in the preset-project activity creation flow. A user with ...
packagist
No PRs yet
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_fie...
CPANSA-Mojolicious-2026-15747 CVE-2026-15747 17 days ago
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf...
cpan
No PRs yet
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could b...
CPANSA-DBI-2026-60082 CVE-2026-60082 17 days ago
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the sourc...
cpan
No PRs yet
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_mat...
CPANSA-DBI-2026-15043 CVE-2026-15043 17 days ago
DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL eng...
cpan
No PRs yet
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume av...
CPANSA-DBI-2026-60081 CVE-2026-60081 17 days ago
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an ar...
cpan
No PRs yet
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the...
CPANSA-DBI-2026-15392 CVE-2026-15392 17 days ago
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method bu...
cpan
No PRs yet
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass
GHSA-vrr2-g9gh-c3jc CVE-2026-52820 MODERATE 17 days ago
## Summary The Timesheet API `PATCH /api/timesheets/{id}` and `POST /api/timesheets` endpoints accept a user-supplied `project` ID and resolve it ...
packagist
No PRs yet
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target
GHSA-4m8q-55qv-9pwp CVE-2026-52819 MODERATE 17 days ago
## Summary `GET /api/timesheets?user=<id>` (and `users[]=<id>`) returns the targeted user's timesheet records to any caller that has the `view_oth...
packagist
No PRs yet
Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes
GHSA-pgcc-vfmc-7cw5 CVE-2026-49992 MODERATE 17 days ago
### Summary Kimai 2.56.0 contains authenticated cross-site request forgery issues in its default team creation shortcuts for projects, customers, ...
packagist
No PRs yet
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
GHSA-8f6j-263m-g72x MODERATE 17 days ago
### Summary `SignedDataVerifier` attempts to perform online revocation checking when `enable_online_checks=True`, but its OCSP validation logic acc...
pypi
No PRs yet
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
GHSA-xf7x-x43h-rpqh HIGH 17 days ago
## Circular JSON Schema `$ref` causes unbounded CPU DoS in `json_repair` ### Summary `SchemaRepairer.resolve_schema()` in `json_repair` follows J...
pypi
No PRs yet
FacturaScripts: Account takeover of any 2FA-enabled user
GHSA-c67f-gmxw-mj93 CVE-2026-47677 CRITICAL 17 days ago
# Authentication bypass in FacturaScripts: `/login?action=two-factor-validation` accepts brute-forceable TOTP without password or CSRF protection ...
packagist
No PRs yet
DIRAC: SQL injection and lack of access control in PilotManager service
GHSA-7xw9-549r-8jrc HIGH 17 days ago
### Details A number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping o...
pypi
No PRs yet
DIRAC: Pilot code downloaded over unverified HTTPS connection
GHSA-vg99-gr89-qhw9 CVE-2026-61668 HIGH 17 days ago
### Summary The second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certific...
pypi
No PRs yet
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
GHSA-m4m7-4cw8-62j6 CVE-2026-61667 CRITICAL 17 days ago
### Summary The FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerab...
pypi
No PRs yet
Apollo ConfigService access key authentication bypass via raw config file appId parsing
GHSA-h4pc-58cc-hc95 CVE-2026-59955 HIGH 17 days ago
### Summary Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey / management key authentication is enabled ...
maven
No PRs yet
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
GHSA-4w3q-qpfq-v992 CVE-2026-59954 HIGH 17 days ago
### Summary Apollo ConfigService may allow unauthorized access to configuration data when AccessKey / management key authentication is enabled and ...
maven
No PRs yet
Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
EEF-CVE-2026-58228 GHSA-5cgh-g58j-m9cq CVE-2026-58228 MEDIUM 17 days ago
## Summary Cross-site scripting vulnerability in phoenixframework phoenix\_live\_view allows an attacker to bypass URL scheme validation and execu...
hex
No PRs yet
NukeViet: Pre-authentication SSRF via X-Forwarded-Host
GHSA-4chg-4752-w88r CVE-2026-55372 HIGH 17 days ago
## Summary An unauthenticated attacker can coerce the server into issuing HTTP requests to an attacker-chosen host by spoofing the `X Forwarded-Ho...
packagist
No PRs yet
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
GHSA-c9xg-64p9-f2jj CVE-2026-54065 HIGH 17 days ago
## Summary Path Traversal to Arbitrary File Deletion in the Edit Comment admin function. An authenticated administrator can delete arbitrary files...
packagist
No PRs yet