An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

35,373

Total Advisories

3,132

With Dependabot PRs

4,601

Critical Severity

12,388

High Severity

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
GHSA-529h-vh3j-85hq CVE-2026-49981 HIGH about 1 month ago
### Description The per-template filter, tag and function allow-list check is compiled into the `checkSecurity()` method of each `Template` subcla...
packagist
No PRs yet
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
GHSA-3ccm-4qq2-5wrp MODERATE about 1 month ago
## Summary `ciphertextContainer.UnmarshalJSON` decodes the third `:`-separated component of a `vault:vX:base64...` ciphertext and then uncondition...
go
No PRs yet
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
GHSA-6c87-g9pw-78fx LOW about 1 month ago
# Summary `Config.registryFor` selected a per-registry credential / CA / mirror block by checking `strings.HasSuffix(name, fqdn)` after stripping ...
go
No PRs yet
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
GHSA-gvpp-v77h-5w8g CVE-2026-49986 HIGH about 1 month ago
## Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` ### Summary The Cortex MCP server (`neuro-cortex-memory`) treats the `CLAU...
pypi
No PRs yet
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
GHSA-hwmc-r6mf-jh83 LOW about 1 month ago
Schema.org has a cross-site scripting (XSS) vulnerability via script break-out in toScript() output.
packagist
No PRs yet
wetty vulnerable to DOM XSS via file-download filename
GHSA-p26j-h7wj-r568 CVE-2026-49864 HIGH about 1 month ago
### Summary The wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string ...
npm
No PRs yet
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
GHSA-2wwr-9x6f-88gp MODERATE about 1 month ago
EasyAdminBundle ships two public Twig components — `<twig:ea:Flag countryCode="...">` and `<twig:ea:Icon name="...">` — that load SVG files from di...
packagist
No PRs yet
auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
GHSA-pvrj-8cg3-j5f8 CVE-2026-49857 HIGH about 1 month ago
## SSRF Protection Bypass via IPv4-mapped IPv6 Loopback ### Summary `auth-fetch-mcp` v3.0.1 implements SSRF protection in `assertSafeUrl()` (`src...
npm
No PRs yet
@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization
GHSA-c5r6-m4mr-8q5j CVE-2026-49856 MODERATE about 1 month ago
## Summary The network domain has a central SSRF authorization policy that blocks private, loopback, link-local, and reserved targets unless an ex...
npm
No PRs yet
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
GHSA-582q-v28r-7cxr CVE-2026-46487 HIGH about 1 month ago
### Summary GeoNetwork's Elasticsearch-backed search API is responsible for injecting access-control and visibility filters into every request befo...
maven
No PRs yet
GeoNetwork has reflected XSS through client-side template injection
GHSA-2v4m-fw6c-g78f CVE-2026-39379 HIGH about 1 month ago
### Summary It is possible to craft a URL that causes GeoNetwork to reflect attacker-controlled content into an error page in a way that gets evalu...
maven
No PRs yet
Open Babel has out-of-bounds write in MSI translationVectors[]
GHSA-f8h2-c479-vqxf CVE-2022-46295 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's MSI parser allowed an out-of-bounds write into the `translationVectors[]` array when rea...
pypi
No PRs yet
Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)
GHSA-mjmg-352j-f456 CVE-2022-46294 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's MOPAC input parser allowed an out-of-bounds write into the `translationVectors[]` array ...
pypi
No PRs yet
Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
GHSA-7h6r-6p76-68c9 CVE-2022-46293 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's MOPAC output parser allowed an out-of-bounds write into the `translationVectors[]` array...
pypi
No PRs yet
Open Babel has out-of-bounds write in Gaussian translationVectors[]
GHSA-jg3h-pv7c-4f9c CVE-2022-46291 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's Gaussian output parser allowed an out-of-bounds write into the `translationVectors[]` ar...
pypi
No PRs yet
Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)
GHSA-5rff-8f7c-8jmw CVE-2022-46290 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's ORCA parser allowed an out-of-bounds write when reading a crafted input file. ### Detai...
pypi
No PRs yet
Open Babel has out-of-bounds write in ORCA nAtoms parser
GHSA-rj4c-r689-cm87 CVE-2022-46289 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's ORCA parser allowed an out-of-bounds write when reading a crafted input file. ### Detai...
pypi
No PRs yet
Open Babel has uninitialized pointer dereference in PQS pFormat
GHSA-8qxc-57hf-hc9j CVE-2022-46280 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's PQS parser caused an uninitialized pointer dereference when reading a crafted input file...
pypi
No PRs yet
Open Babel has uninitialized pointer dereference in MSI atom parser
GHSA-jr2x-6qf6-q5mc CVE-2022-44451 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's MSI parser caused an uninitialized pointer dereference when reading a crafted input file...
pypi
No PRs yet
Open Babel has out-of-bounds write in MOL2 attribute/value parser
GHSA-vjg6-gm8m-v5g6 CVE-2022-43607 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's MOL2 parser allowed an out-of-bounds write when reading a crafted input file. ### Detai...
pypi
No PRs yet
Open Babel has out-of-bounds write in PQS coord_file parser
GHSA-f29h-2h58-48r7 CVE-2022-43467 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's PQS parser allowed an out-of-bounds write when reading a crafted input file. ### Detail...
pypi
No PRs yet
Open Babel has uninitialized pointer dereference in GRO residue parser
GHSA-mw5r-wq2m-397c CVE-2022-42885 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's GRO parser caused an uninitialized pointer dereference when reading a crafted input file...
pypi
No PRs yet
Open Babel has out-of-bounds write in CSR PadString (title field)
GHSA-p594-7xw4-g76p CVE-2022-41793 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's CSR parser allowed an out-of-bounds write when reading a crafted input file. ### Detail...
pypi
No PRs yet
Open Babel has out-of-bounds write in Gaussian coords_type orientation parser
GHSA-vr3p-gg26-45v9 CVE-2022-37331 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's Gaussian output parser allowed an out-of-bounds write when reading a crafted input file....
pypi
No PRs yet
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
GHSA-m982-7q3h-r784 CVE-2025-11000 MODERATE about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's PQS parser caused an out-of-bounds (pre-buffer) read when reading a crafted input file. ...
pypi
No PRs yet
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
GHSA-55j6-rjhx-hwfh CVE-2025-10999 MODERATE about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's CACAO parser caused a NULL pointer dereference when reading a crafted input file. ### D...
pypi
No PRs yet
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
GHSA-j9pp-7wfg-q7fj CVE-2025-10998 LOW about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's ChemKin parser caused a NULL pointer dereference when reading a crafted input file. ###...
pypi
No PRs yet
Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies
GHSA-8wq6-qh76-wpv9 CVE-2025-10997 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's ChemKin parser caused a heap buffer overflow when reading a crafted input file. ### Det...
pypi
No PRs yet
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was ...
CPANSA-HTML-Gumbo-2025-15646 CVE-2025-15646 about 1 month ago
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0...
cpan
No PRs yet
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All thre...
CPANSA-CGI-Session-2026-56016 CVE-2026-56016 about 1 month ago
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the s...
cpan
No PRs yet
Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
GHSA-j35x-w4gj-pf7w CVE-2025-10996 HIGH about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's SMILES parser caused a heap buffer overflow when reading a crafted input string. ### De...
pypi
No PRs yet
Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
GHSA-8j3x-m868-cpw8 CVE-2025-10995 LOW about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's bundled zipstream decompression code caused an out-of-bounds write via overlapping `memc...
pypi
No PRs yet
Paymenter has race condition in payWithCredit() that enables credit double-spend
GHSA-pgcq-8grm-5rx9 CVE-2026-55219 MODERATE about 1 month ago
### Summary The credit payment implementation in `app/Livewire/Invoices/Show.php` executes a pessimistic row lock (`lockForUpdate()`) outside of an...
packagist
No PRs yet
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
GHSA-pp85-5j63-xpq3 CVE-2025-10994 LOW about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's GAMESS output parser caused a use-after-free when reading a crafted input file. ### Det...
pypi
No PRs yet
Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
GHSA-rxpr-wq63-jr7p CVE-2026-3408 LOW about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's CDXML file format parser caused a NULL pointer dereference when reading a crafted input ...
pypi
No PRs yet
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
GHSA-4w5w-4fhm-q483 CVE-2026-2705 LOW about 1 month ago
### Summary A memory-safety vulnerability in Open Babel's MOL2 file format parser caused a NULL pointer dereference when reading a crafted input f...
pypi
No PRs yet
Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
GHSA-6xw4-2g22-26h8 CVE-2026-2704 LOW about 1 month ago
> ### Summary > > A memory-safety vulnerability in Open Babel's CIF file format parser > allowed an out-of-bounds read when reading a crafted input...
pypi
No PRs yet
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
GHSA-h8vq-8gpg-mhcg CVE-2026-48808 MODERATE about 1 month ago
### Description This is a residual bypass of CVE-2026-46635 / GHSA-vcc8-phrv-43wj that only affects sandboxing enabled through `SourcePolicyInterf...
packagist
No PRs yet
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
GHSA-8x9c-rmqh-456c CVE-2026-48807 MODERATE about 1 month ago
### Description This is a residual bypass of CVE-2026-47732 / GHSA-pr2w-4gpj-cpq4 left after the initial fix for unguarded `__toString()` calls. I...
packagist
No PRs yet
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
GHSA-5v5v-ww74-355v CVE-2026-48806 MODERATE about 1 month ago
### Description This is a residual bypass of CVE-2026-47732 / GHSA-pr2w-4gpj-cpq4 left after the initial fix for unguarded `__toString()` calls. ...
packagist
No PRs yet
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
GHSA-p42q-9prx-q5wq CVE-2026-48805 LOW about 1 month ago
### Description The 3.26.0 source-policy hardening changed the signature of `CoreExtension::checkArrow()` to take a boolean `$isSandboxed` instead...
packagist
No PRs yet
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
GHSA-9c54-x2g4-v92j CVE-2026-49835 MODERATE about 1 month ago
### Impact An unauthenticated remote attacker can trigger unbounded memory growth on the timestamp authority server. This vulnerability exists be...
go
No PRs yet
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
GHSA-f5mr-q85p-6hh6 CVE-2026-49478 HIGH about 1 month ago
## Impact Three security vulnerabilities were identified in the OIDC Discovery client: 1. **Blind Server-Side Request Forgery (SSRF) via Cross-Ho...
go
No PRs yet
CefSharp.Common: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
GHSA-85jm-cwp2-mvpv CVE-2026-48796 MODERATE about 1 month ago
### Summary `FolderSchemeHandlerFactory` was intended to restrict served files to a configured `rootFolder`, but its path validation used a raw st...
nuget
No PRs yet
@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
GHSA-qcm7-3vpr-hj5h CVE-2026-48795 HIGH about 1 month ago
### Summary The fix for [GHSA-f5x2-vj4h-vg4c](https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c) / CVE-2026-25754 introduce...
npm
No PRs yet
oban_web missing authorization check on `save-job` event handler
GHSA-389x-rgxr-8m33 CVE-2026-48592 MODERATE about 1 month ago
### Summary `oban_web` 2.12.0 through the current unpatched release exposes a `save-job` LiveView event handler that performs no authorization che...
hex
No PRs yet
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
GHSA-6xh2-93p9-vqh4 CVE-2026-48593 MODERATE about 1 month ago
### Summary `oban_web` 2.12.0 introduced a cron expression parser that expands `-`-separated ranges without validating the endpoints. An attacker ...
hex
No PRs yet
Probo has an open redirect bypass via path normalization
GHSA-x7qq-m748-8p2c CVE-2026-49820 MODERATE about 1 month ago
### Impact Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors,...
go
No PRs yet
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
GHSA-m63v-2g9w-2w6v CVE-2026-50566 CRITICAL about 1 month ago
### Summary A follow-up bypass of the round-4 PodSpec hardening (GHSA-gx55-f84r-v3r7, GHSA-wmgg-3p4h-48x7, GHSA-v455-mv2v-5g92). Those advisories ...
go
No PRs yet
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
GHSA-8wcj-mfrc-jx5q CVE-2026-50565 MODERATE about 1 month ago
### Summary Fission builder pods were created with `ServiceAccountName: fission-builder` and no `AutomountServiceAccountToken: false`, so the kube...
go
No PRs yet