Security Advisories
Browse security advisories and track which Dependabot PRs address them.
35,199
Total Advisories
3,112
With Dependabot PRs
4,571
Critical Severity
12,338
High Severity
jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow
GHSA-5pmv-rx8r-wmv5 CVE-2026-52834 HIGH about 1 month ago
### Summary
On 32-bit platforms, decoding a crafted image may lead to out-of-bounds writes due to integer overflow in length calculation.
### Det...
cargo
No PRs yet
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
GHSA-66m8-c62j-h6v5 MODERATE about 1 month ago
### Summary
`jxl-oxide` exposes a public safe API that can construct an undersized `FrameBuffer` due to unchecked `usize` multiplication, which imm...
cargo
No PRs yet
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
GHSA-2v8p-fqpx-2q3w MODERATE about 1 month ago
### Summary
Logic bug in `decode_simple_table_slow` may cause integer arithmetic overflow when decoding Modular image with certain kind of MA tree,...
cargo
No PRs yet
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
GHSA-j5mc-p8qg-39j7 LOW about 1 month ago
### Summary
Kimai 2.56.0 contains an authenticated improper authorization / IDOR vulnerability in the favorite timesheet add and remove endpoints....
packagist
No PRs yet
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
GHSA-794g-x443-36f7 CVE-2026-2092 HIGH about 1 month ago
Keycloak's SAML broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a va...
maven
No PRs yet
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
GHSA-rxw2-pc8j-vxwm CVE-2026-52830 CRITICAL about 1 month ago
## Summary
fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact...
pypi
No PRs yet
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
GHSA-4j9m-h44m-2hv8 CVE-2026-50268 LOW about 1 month ago
### Summary
Configuring `encrypt:rsa:algorithm=OAEP` does not enable OAEP encryption. Due to an incorrect BouncyCastle transformation string, the ...
nuget
No PRs yet
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
GHSA-rxrh-4j9h-xgg9 CVE-2026-50267 MODERATE about 1 month ago
### Summary
When MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those cre...
nuget
No PRs yet
Steeltoe's static JWKS cache shared across schemes and never invalidated
GHSA-7fqc-p256-7pwj CVE-2026-50202 MODERATE about 1 month ago
### Summary
The JWT signing key cache in `TokenKeyResolver` uses `kid` as the sole cache key without namespacing by authority. In applications wit...
nuget
No PRs yet
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
GHSA-227r-jm2g-7cp4 CVE-2026-50201 MODERATE about 1 month ago
### Summary
All Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`, which is mapped to Cloud Foundry's `read_basic_data` perm...
nuget
No PRs yet
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
GHSA-q62h-354g-5r85 CVE-2026-50200 HIGH about 1 month ago
### Summary
The `Sanitizer` component in the Environment actuator redacts configuration values by matching the configuration key name against a su...
nuget
No PRs yet
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
GHSA-j8ph-6fxj-g533 CVE-2026-50196 HIGH about 1 month ago
### Summary
`DataCenterInfo.FromJson` throws `ArgumentException` for any `name` value other than `"MyOwn"` or `"Amazon"`, despite the Java Eureka ...
nuget
No PRs yet
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
GHSA-58f6-6rj2-3v8r CVE-2026-50194 HIGH about 1 month ago
### Summary
When Steeltoe management endpoints are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the midd...
nuget
No PRs yet
SimpleSAMLphp has Possible DoS via XPath Transform
GHSA-5cjr-mxj5-wmrx CVE-2026-49289 HIGH about 1 month ago
## Summary
This library turned out to be vulnerable to Denial-of-Service attacks using XPath transforms. A mitigation has been put in place to res...
packagist
No PRs yet
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
GHSA-63wg-wjjj-7cp8 CVE-2026-52829 HIGH about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node listens on the default `[::]` address on a ...
cargo
No PRs yet
SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass
GHSA-6929-8p9f-26jx CVE-2026-49283 HIGH about 1 month ago
## Summary
SimpleSAMLphp's HTTP-Artifact receive path can treat an unsigned embedded SAML `Response` as cryptographically valid for the wrong IdP....
packagist
No PRs yet
Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments
GHSA-8w6w-23mq-h8rg CVE-2026-52817 HIGH about 1 month ago
### Summary
In the [Debian.sudoers](https://github.com/Linuxfabrik/monitoring-plugins/blob/main/assets/sudoers/Debian.sudoers) file, `apt-get` is a...
pypi
No PRs yet
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
GHSA-x4hg-hfwf-p9mw MODERATE about 1 month ago
## Summary
The `HTMLInputElement.checkValidity()` method constructed a `RegExp` directly from the user-controlled `pattern` property without any s...
npm
No PRs yet
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
GHSA-322x-v876-g883 HIGH about 1 month ago
## Summary
The `matchFileSnapshot` function in `src/assertions/snapshots.ts` accepted a `filePath` parameter with zero validation. When snapshot u...
npm
No PRs yet
9router: Missing Authorization and OS Command Injection
GHSA-g6g7-pvmx-m74p CVE-2026-59800 CRITICAL about 1 month ago
# Unauthenticated RCE via `/api/tunnel/tailscale-install`
**Affected:** `9router` (npm package) — current master (`v0.4.39`).
### Summary
`POST ...
npm
No PRs yet
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
GHSA-gj2h-2fpw-fhv9 MODERATE about 1 month ago
### Summary
`UForm` and `UAuthForm` render a server-side `<form>` element with no `method` and no `action` attribute, relying on a hydrated `@subm...
npm
No PRs yet
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
GHSA-86vw-mfpg-wwv9 CVE-2026-52746 HIGH about 1 month ago
### Impact
In JSONata `<v2.2.0`, it is possible to craft non-matching inputs to the [$toMillis](https://docs.jsonata.org/date-time-functions#tomill...
npm
No PRs yet
zebrad has unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention
GHSA-65jj-fmw8-468q CVE-2026-52734 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbound P2P connections (`network.l...
cargo
No PRs yet
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
GHSA-2gf8-q9rr-jq3h CVE-2026-52733 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node participates in a network where chain forks...
cargo
No PRs yet
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
GHSA-3w32-23wj-rxg3 CVE-2026-50282 HIGH about 1 month ago
We have identified an authorization issue in Craft CMS where a forced folder move can delete a conflicting destination folder without destination d...
packagist
No PRs yet
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
GHSA-x5m4-g2cq-52pq CVE-2026-50281 HIGH about 1 month ago
## Summary
There is a mass-assignment flaw in the bulk-duplicate element action. Alice, holding only the permission to duplicate an entry she owns...
packagist
No PRs yet
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
GHSA-5hvg-w58j-545m CVE-2026-9811 MODERATE about 1 month ago
### Summary
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus ...
packagist
No PRs yet
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
GHSA-7h65-whp7-rgqf CVE-2026-9809 HIGH about 1 month ago
### Summary
A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popove...
packagist
No PRs yet
Mautic has an Authorization Bypass in API v2 Endpoints
GHSA-2jrw-c95w-h43g CVE-2026-9808 HIGH about 1 month ago
### Summary
An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles...
packagist
No PRs yet
Mautic vulnerable to Path Traversal via Campaign Import
GHSA-6r9h-4h75-7q4x CVE-2026-9559 CRITICAL about 1 month ago
### Summary
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign im...
packagist
No PRs yet
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
GHSA-9fx4-7cmj-47vg CVE-2026-9558 CRITICAL about 1 month ago
### Summary
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates wit...
packagist
No PRs yet
Mautic Focus component Vulnerable to SSRF
GHSA-jmv8-8j9j-rcpc CVE-2026-9557 MODERATE about 1 month ago
### Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in the Mautic Focus component (`MauticFocusBundle`). Under certain conditions...
packagist
No PRs yet
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection
GHSA-hhm7-qrv5-h4r6 CVE-2026-52739 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node processes blocks past the checkpoint height...
cargo
No PRs yet
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks
GHSA-w834-cf6p-9m9w CVE-2026-52738 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node processes blocks on any Zcash network.
###...
cargo
No PRs yet
Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block
GHSA-gvjc-3w7c-92jx CVE-2026-52737 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbound P2P connections and is sync...
cargo
No PRs yet
zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
GHSA-gf9r-m956-97qx CVE-2026-52735 CRITICAL about 1 month ago
### Am I affected
You are affected if:
1. You run any version of `zebrad` up to and including `v4.4.1`.
2. Your node validates blocks on mainnet,...
cargo
No PRs yet
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
GHSA-4m69-67m6-prqp CVE-2026-52736 HIGH about 1 month ago
## Description
### Am I affected
You are affected if:
1. You run any version of `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbo...
cargo
No PRs yet
Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
GHSA-h72h-ppcx-998p LOW about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbound P2P connections (`network.l...
cargo
No PRs yet
zebrad has mempool transaction admission denial via single-peer inbound queue saturation
GHSA-4fc2-h7jh-287c CVE-2026-52732 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbound P2P connections (`network.l...
cargo
No PRs yet
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
GHSA-c8w6-x74f-vmg3 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your `zebrad.toml` sets `rpc.listen_addr` to a TCP ad...
cargo
No PRs yet
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
GHSA-f9ff-5x35-7gfw HIGH about 1 month ago
## Summary
Authorization for scoped (agent) MCP callers is enforced **inline, per tool**, and is applied inconsistently — several mutating tools s...
npm
No PRs yet
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
GHSA-443g-gwgp-49x4 LOW about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbound P2P connections.
### Summa...
cargo
No PRs yet
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate
GHSA-qv2r-v3mx-f4pf CVE-2026-52731 MODERATE about 1 month ago
### Am I affected
You are affected if:
1. You run `zebrad` up to and including `v4.4.1`.
2. Your `zebrad.toml` sets `rpc.listen_addr` to a TCP ad...
cargo
No PRs yet
Mautic has SQL Injection in API Contact Filtering
GHSA-fcmw-wx57-9p75 CVE-2026-4776 HIGH about 1 month ago
### Summary
An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested...
packagist
No PRs yet
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
GHSA-q4rm-m6xh-5pv7 MODERATE about 1 month ago
## Summary
The `Mysqls.add` API command (`lib/Froxlor/Api/Commands/Mysqls.php`) accepts a customer-controlled `mysql_server` parameter and only va...
packagist
No PRs yet
Froxlor: Authenticated customers can read other customers' allowed sender aliases
GHSA-mr9h-45p9-fg8h MODERATE about 1 month ago
## Summary
An authenticated customer can read other customers' allowed sender aliases from Froxlor's sender-delete confirmation page when `mail.en...
packagist
No PRs yet
electerm has Command Injection in File System Operations (rmrf, mv, cp)
GHSA-v5ff-xmfp-p245 CVE-2026-49255 HIGH about 1 month ago
### Impact
A command injection vulnerability exists in electerm's file system operations (`rmrf`, `mv`, `cp`) in `src/app/lib/fs.js`. These functi...
npm
No PRs yet
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth
GHSA-4q9j-6299-gxmr CVE-2026-49254 LOW about 1 month ago
### Summary
The Dragonfly Manager exposes `GET /api/v1/oauth` and `GET /api/v1/oauth/:id` to unauthenticated clients. The response body deserializ...
go
No PRs yet
electerm has Path Traversal in Zmodem and Trzsz Download Filename Handling
GHSA-38j7-23hf-9mhc CVE-2026-49253 HIGH about 1 month ago
### Impact
A path traversal vulnerability exists in the Zmodem and Trzsz file download handlers in electerm. When receiving files via Zmodem or Tr...
npm
No PRs yet
@conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
GHSA-525m-7f82-2mf7 CVE-2026-49250 HIGH about 1 month ago
A CPU exhaustion vulnerability exists in Conform's [`parseSubmission`](https://conform.guide/api/react/future/parseSubmission) future API when pars...
npm
No PRs yet