Security Advisories
Browse security advisories and track which Dependabot PRs address them.
35,093
Total Advisories
3,110
With Dependabot PRs
4,562
Critical Severity
12,297
High Severity
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
GHSA-465g-4q99-5x86 CVE-2026-54064 HIGH 17 days ago
## Summary
Two filter-bypass techniques in `NukeViet\Core\Request::filterAttr()` and `NukeViet\Core\Request::unhtmlentities()` allow a low-privile...
packagist
No PRs yet
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
GHSA-w2w5-w2pw-r929 CVE-2026-49259 HIGH 17 days ago
## Summary
A stored cross-site scripting (XSS) vulnerability exists in NukeViet CMS versions 4.x through 4.5.08. A low-privileged authenticated us...
packagist
No PRs yet
NukeViet: Unauthenticated Reflected XSS in Comment Module
GHSA-mxpf-qgg6-v3ff CVE-2026-48118 HIGH 17 days ago
## Summary
Reflected XSS in the Comment module via the `status_comment` URL parameter. The parameter accepts attacker-controlled base64-encoded HT...
packagist
No PRs yet
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
GHSA-9jpv-c7p4-997x CVE-2026-45579 CRITICAL 17 days ago
### Summary
An remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated...
pypi
No PRs yet
Decidim: Push subscriptions can be abused for server-side requests
GHSA-2g9c-vf8h-prxx CVE-2026-45573 MODERATE 17 days ago
## Description
The push-subscription endpoint stores an attacker-controlled delivery URL, and the notification send path becomes an outbound-reque...
rubygems
No PRs yet
Decidim: HTML content blocks allow stored script execution
GHSA-533c-2vh9-4r86 CVE-2026-45572 MODERATE 17 days ago
## Description
A privileged admin user who can edit an affected landing page can store arbitrary HTML/JavaScript in an `HTML block`, and the publ...
rubygems
No PRs yet
Decidim: CSV census record endpoints improper authorization
GHSA-q79h-67vx-m9xg CVE-2026-45415 MODERATE 17 days ago
## Description
A participant manager can access and modify the CSV census record admin forms.
## Technical description
The CSV census admin reco...
rubygems
No PRs yet
Decidim: JWT-backed authentication can be replayed across organizations
GHSA-r3v7-5x4c-c69q CVE-2026-45414 HIGH 17 days ago
## Description
A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL `participantDetails` field for an...
rubygems
No PRs yet
Decidim: Verification documents can be downloaded through reusable links
GHSA-3mvf-82qp-8qh5 CVE-2026-45378 HIGH 17 days ago
## Description
Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed `...
rubygems
No PRs yet
Decidim: Private exports can be downloaded through reusable links
GHSA-767h-63j4-5226 CVE-2026-45377 MODERATE 17 days ago
## Description
The normal `download_your_data` flow requires the requester to be logged in as the export owner, but the resulting Active Storage b...
rubygems
No PRs yet
Decidim: Admin user search allows SQL injection through similarity-based sorting
GHSA-jvqq-cvh4-xm37 CVE-2026-45376 MODERATE 17 days ago
The admin organization user search uses the untrusted term value inside raw SQL ORDER BY expressions. Because the value is interpolated before Rail...
rubygems
No PRs yet
Decidim: Verification admins can access supplied IDs from other organizations
GHSA-86fh-w43w-338c CVE-2026-45330 MODERATE 17 days ago
## Description
The verification admin mutation flow allows accessing, verifying, and rejecting participants records from another tenant.
## Techn...
rubygems
No PRs yet
Decidim: Forms admin question editor lacks authorization
GHSA-vq6j-hj8w-7v39 CVE-2026-45086 MODERATE 17 days ago
## Description
A participant can load the demographics questionnaire admin editor and make changes.
## Technical description
The demographics qu...
rubygems
No PRs yet
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
GHSA-jxpj-9j24-w337 CVE-2025-32781 MODERATE 17 days ago
### Summary
Apollo Portal versions before 2.5.0 do not verify application and namespace permissions when an authenticated user requests a release ...
maven
No PRs yet
GeoNode: Stored XSS to full account takeover
GHSA-rwcv-whm8-fmxm CVE-2024-27091 MODERATE 17 days ago
An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is...
pypi
No PRs yet
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large re...
CPANSA-perl-2026-57432 CVE-2026-57432 18 days ago
Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_str...
cpan
No PRs yet
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between...
CPANSA-perl-2026-13221 CVE-2026-13221 18 days ago
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is ...
cpan
No PRs yet
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I3...
CPANSA-Storable-2026-57433 CVE-2026-57433 18 days ago
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a si...
cpan
No PRs yet
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via extensions(), extensions_by_long_name(), extensions_by_oid(), or has_extension_o...
CPANSA-Crypt-OpenSSL-X509-2026-58102 CVE-2026-58102 18 days ago
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building...
cpan
No PRs yet
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. basicC, ia5string, and auth_att dereference its result without a N...
CPANSA-Crypt-OpenSSL-X509-2026-58101 CVE-2026-58101 18 days ago
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an...
cpan
No PRs yet
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
GHSA-g936-7jqj-mwv8 CRITICAL 20 days ago
## Description
A vulnerability was discovered in TSDProxy where it forwards its internal per-process authentication token to all proxied backend s...
go
No PRs yet
melange: Incomplete package integrity verification allows data section substitution
GHSA-fpg8-7664-jc5q CVE-2026-54174 HIGH 20 days ago
Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the a...
go
No PRs yet
Excon does not redact additional sensitive/risky headers when following redirects
GHSA-48rx-c7pg-q66r CVE-2026-54171 MODERATE 20 days ago
### Impact
The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way...
rubygems
No PRs yet
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
GHSA-h4g2-xfmw-q2c9 HIGH 20 days ago
### Summary
A Clauster instance bound to a **non-loopback** address (e.g. `0.0.0.0` or a LAN IP) can serve the entire dashboard and its API **witho...
pypi
No PRs yet
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
GHSA-rqq5-2gf9-4w4q CVE-2026-54163 MODERATE 20 days ago
## Summary
`secure_headers` builds the `Content-Security-Policy` value by stitching every configured directive together with `; ` separators. Thre...
rubygems
No PRs yet
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
GHSA-56mp-4f3v-fgj2 CVE-2026-50551 CRITICAL 20 days ago
SiYuan v3.6.5 and earlier versions contain a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer t...
go
No PRs yet
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
GHSA-m5f5-28qr-9g9r CVE-2026-54159 CRITICAL 20 days ago
### Impact
A PHP Object Injection vulnerability affects the PrestaShop module `ps_facetedsearch`.
The module rebuilds the selected search filters...
packagist
No PRs yet
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
GHSA-5xfx-xj4h-5p7r CVE-2026-54158 CRITICAL 20 days ago
### Summary
The attribute-view (database) cell renderer `genAVValueHTML` interpolates cell content raw in four of its branches: `text`, `url`, `ph...
go
No PRs yet
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
GHSA-g5r6-gv6m-f5jv HIGH 20 days ago
### Summary
`confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP cl...
pypi
No PRs yet
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-wm45-qh3g-v83f HIGH 20 days ago
### Summary
A client that can invoke MCP tools can read **arbitrary files from the server host** and exfiltrate them as Atlassian attachments. The...
pypi
No PRs yet
SafeInstall agent guard shell parsing can miss raw package execution
GHSA-xrmc-c5cg-rv7x HIGH 20 days ago
## Summary
SafeInstall CLI through 0.10.1 can fail to recognize some package-manager and registry-runner commands in its agent guard. Case-variant...
npm
No PRs yet
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
GHSA-qv4m-m73m-8hj7 HIGH 20 days ago
#### Summary
An authenticated user with the HR "Manage Employees" permission (`SA_EMPLOYEE`) can upload a file with an arbitrary extension through ...
packagist
No PRs yet
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
GHSA-m8gf-v64p-gfmg CVE-2026-54071 HIGH 20 days ago
## Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
### Summary
BabelDOC's vendored PDF parser (`babeldoc/...
pypi
No PRs yet
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
GHSA-m93h-4hw7-5qcm CVE-2026-54088 CRITICAL 20 days ago
## Overview
The Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. Use...
go
No PRs yet
`exploration` was removed from crates.io for malicious code
GHSA-99j7-fhr2-xfj4 CRITICAL 20 days ago
A method within the `exploration` crate attempted to download and execute a payload from a remote site.
The malicious crate had 1 version publishe...
cargo
No PRs yet
Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search
GHSA-2ppx-66jv-wpw5 CVE-2026-54136 MODERATE 20 days ago
### Summary
A resource-scoped API token can read script contents outside its allowed path scope via `GET /api/w/{workspace}/scripts/list_search`.
...
cargo
No PRs yet
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
GHSA-w7cg-whh7-xp28 CVE-2026-54070 HIGH 20 days ago
## Summary
`renderPackageREADME` in `kernel/bazaar/readme.go` renders a Bazaar package README from Markdown to HTML with the lute engine and `SetS...
go
No PRs yet
File Browser: Authentication Bypass via Proxy Auth Header Forgery
GHSA-xqp3-jq6g-x3qm CVE-2026-54089 CRITICAL 20 days ago
## Summary
When FileBrowser is configured with proxy authentication (`auth.method=proxy`), any unauthenticated attacker who can reach the server d...
go
No PRs yet
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
GHSA-hvr9-72v2-fff3 CVE-2026-54069 CRITICAL 20 days ago
## Summary
SiYuan Note's kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every...
go
No PRs yet
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
GHSA-gcm7-57gf-953c CVE-2026-54068 MODERATE 20 days ago
### Summary
The `/api/icon/getDynamicIcon` endpoint is explicitly excluded from authentication in SiYuan's kernel router (`router.go`, "不需要鉴权" -- ...
go
No PRs yet
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
GHSA-9mqm-qcwf-5qhg MODERATE 20 days ago
### Summary
CredSweeper's deep scanner does not enforce `recursive_limit_size` as a hard limit. Several recursive scanners fully decompress or full...
pypi
No PRs yet
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
GHSA-h69g-9hx6-f3v4 CVE-2026-54063 HIGH 20 days ago
## Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
### Summary
The `checkSheet()` function in `github.com/xuri/excel...
go
No PRs yet
Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL
GHSA-h29v-hj44-q8cv CVE-2026-54072 CRITICAL 20 days ago
## Summary
The `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `res...
go
No PRs yet
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
GHSA-mvjr-vv3c-w4qv CVE-2026-54067 CRITICAL 20 days ago
### Summary
A CSS snippet body containing `</style>` breaks out of its surrounding `<style>` tag when `renderSnippet()` interpolates it via `inser...
go
No PRs yet
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
GHSA-p4m3-mgmm-c664 CVE-2026-54066 HIGH 20 days ago
## Summary
The patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the `/export/` route but the
**identical root caus...
go
No PRs yet
adm-zip: Crafted ZIP file triggers 4GB memory allocation
GHSA-xcpc-8h2w-3j85 CVE-2026-39244 HIGH 20 days ago
adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js l...
npm
6
Dependabot PRs
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
GHSA-489g-7rxv-6c8q MODERATE 20 days ago
### Summary
GHSA-7r34-79r5-rcc9's fix added `validate_url_for_ssrf`, which resolves the attacker-controlled `X-Atlassian-{Jira,Confluence}-Url` hea...
pypi
No PRs yet
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
GHSA-jxj7-g6gm-49j7 CVE-2026-49977 MODERATE 20 days ago
### Summary
tarteaucitron provides a list of cookies and buttons to delete them. If an attacker can write HTML with data attributes, they could cr...
npm
No PRs yet
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
GHSA-cwc9-cp4j-mcvv CVE-2026-49866 HIGH 20 days ago
### Summary
gossipsub processes IHAVE and IWANT control messages by iterating every received message ID synchronously before doing anything with th...
npm
No PRs yet
Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs
GHSA-pj8j-p4g4-4vw8 CVE-2026-49865 MODERATE 20 days ago
### Summary
Kimai 2.56.0 contains a server-side request forgery vulnerability in its invoice PDF preview and generation workflow. If an attacker c...
packagist
No PRs yet