Security Advisories
Browse security advisories and track which Dependabot PRs address them.
34,982
Total Advisories
3,105
With Dependabot PRs
4,555
Critical Severity
12,244
High Severity
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-3hrf-2gc2-mx32 CVE-2026-59860 HIGH 4 days ago
### Summary
Kiota versions **prior to 1.32.3** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink ...
nuget
No PRs yet
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
GHSA-j5g9-f88f-gfj3 CVE-2026-59939 HIGH 4 days ago
### Summary
The `httplib2` HTTP client library performs unbounded decompression of HTTP response bodies encoded with `Content-Encoding: gzip` or `...
pypi
No PRs yet
ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
GHSA-h5r4-w88w-7ccr LOW 4 days ago
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
nuget
No PRs yet
ImageMagick: Memory Leak in ICON decoder when allocation fails
GHSA-h58x-r7f7-rh84 LOW 4 days ago
A memory leak will occur in the ICON decoder when an allocation fails.
nuget
No PRs yet
ImageMagick: Memory leak in VIFF encoder when allocation fails
GHSA-m596-67p7-69wh LOW 4 days ago
When an allocation fails in the VIFF encoder a memory leak will occus.
nuget
No PRs yet
ImageMagick: Memory Leak in MIFF encoder when allocaton fails
GHSA-r628-69v2-2f9c LOW 4 days ago
A memory leak will occur in the MIFF encoder when an allocation fails.
nuget
No PRs yet
ImageMagick: Memory Leak in YUV decoder when opening of blob fails
GHSA-h7f2-f9cc-h2gv LOW 4 days ago
A memory leak will occur when a blob cannot be opened in the YUV decoder.
nuget
No PRs yet
ImageMagick: Memory Leak in TIFF encoder when an allocation fails
GHSA-jfq9-q63x-rc63 LOW 4 days ago
When an allocation fails in the TIFF encoder a small memory leak will occur.
nuget
No PRs yet
ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
GHSA-99w9-hv66-rfv7 LOW 4 days ago
When a blob can not be opened a memory leak will occur when encoding a JNG file.
nuget
No PRs yet
ImageMagick: Memory Leak in hough lines operation when an operation fails
GHSA-j8rh-v2r8-v94x LOW 4 days ago
When a specific operation fails in the hough lines operation a small memory leak will occur.
nuget
No PRs yet
ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
GHSA-7c7m-fpjw-gwcq LOW 4 days ago
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
nuget
No PRs yet
ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
GHSA-6vxp-gfwf-hcr9 LOW 4 days ago
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
nuget
No PRs yet
ImageMagick: Information Disclosure when printing profiles with debug enabled
GHSA-hwf3-r46v-5ggx LOW 4 days ago
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
nuget
No PRs yet
ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
GHSA-qvxh-prvr-85w2 LOW 4 days ago
When a memory allocation fails inside the FormatMagickCaption method a dangling pointer still points to the freed memory.
nuget
No PRs yet
ImageMagick: Use-After-Free when freetype initialization fails
GHSA-6jwg-7q3p-5fqm LOW 4 days ago
When the freetype initialization fails the method does not exit and uses memory that was freed.
nuget
No PRs yet
ImageMagick: Policy Bypass in script operation due to missing checks
GHSA-vghg-5jrg-2398 LOW 4 days ago
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
nuget
No PRs yet
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
GHSA-v3j6-27vc-7pw2 LOW 4 days ago
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
nuget
No PRs yet
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
GHSA-qh5g-q395-cx4j LOW 4 days ago
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
nuget
No PRs yet
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-hc76-7mpc-qjqh MODERATE 4 days ago
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
nuget
No PRs yet
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-56m6-8q75-f2rw MODERATE 4 days ago
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
nuget
No PRs yet
ImageMagick: Policy Bypass possible with matrix-backed operations
GHSA-rvhp-75f6-9jqh LOW 4 days ago
Matrix bases operations like `-canny` are missing a check for allowed memory allocation that could result allocating more memory than allowed.
nuget
No PRs yet
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-4w2j-m93h-cj5j HIGH 4 days ago
## Summary
The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-...
cargo
No PRs yet
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
GHSA-chx6-hx7r-mcp5 CVE-2026-55685 HIGH 4 days ago
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 that covers additional reported scenarios ...
npm
No PRs yet
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-82mp-vp5c-9pf7 CVE-2026-55628 MODERATE 4 days ago
The `-concatenate` operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
nuget
No PRs yet
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
GHSA-c4v7-w88g-m6c4 CVE-2026-55597 MODERATE 4 days ago
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
nuget
No PRs yet
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-qhmf-7fc4-8q3h CVE-2026-55595 MODERATE 4 days ago
When providing invalid arguments to the connected-components option an infinite loop will occur.
nuget
No PRs yet
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
GHSA-mx48-2qq3-23hf CVE-2026-55594 MODERATE 4 days ago
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
nuget
No PRs yet
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
GHSA-g357-x5c3-c72p CVE-2026-55575 HIGH 4 days ago
# `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
**CWE**: CWE-770 (Allocation of Resources Without Limits o...
npm
No PRs yet
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-ff5c-8x9r-8qcw CVE-2026-55510 MODERATE 4 days ago
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
nuget
No PRs yet
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
GHSA-p2f4-r6v6-j797 CVE-2026-54673 HIGH 4 days ago
## Summary
In `electron-builder`'s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only strip...
npm
No PRs yet
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
GHSA-7g7r-gx96-252g CVE-2026-54672 HIGH 4 days ago
### Summary
`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variabl...
npm
No PRs yet
Ruby json: JSON generator heap buffer overflow when streaming to an IO
GHSA-x2f5-4prf-w687 CVE-2026-54696 LOW 5 days ago
### Summary
`JSON.dump(obj, io)` and `JSON::State#generate(obj, io)` can write past the
internal JSON generator buffer when a streamed object cont...
rubygems
1
Dependabot PRs
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
GHSA-w6w4-rjh9-9r58 CVE-2026-55223 MODERATE 5 days ago
### Impact
The JDBC spec defines the interface `DataSource`, with a method called `getConnection()`, and `ConnectionPoolDataSource`, with a method...
maven
No PRs yet
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
GHSA-wrjc-x8rr-h8h6 CVE-2026-53669 MODERATE 5 days ago
This is a follow up to [CVE-2025-68470](https://github.com/remix-run/react-router/security/advisories/GHSA-9jcx-v3wj-wh4m). React Router was alert...
npm
No PRs yet
React Router: Open redirect leading to XSS
GHSA-jjmj-jmhj-qwj2 CVE-2026-53668 MODERATE 5 days ago
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
npm
No PRs yet
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
GHSA-h8fp-f39c-q6mh CVE-2026-53667 MODERATE 5 days ago
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62. React Router was alerted of a code path ...
npm
No PRs yet
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
GHSA-337j-9hxr-rhxg CVE-2026-53666 MODERATE 5 days ago
If application code allows attacker supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for attac...
npm
No PRs yet
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
GHSA-8g53-9m3c-69xg CVE-2026-53467 MODERATE 5 days ago
In the MNG decoder there is a possible heap information disclosure because part of the pixels are left unchanged.
nuget
No PRs yet
find-my-way: DDoS with HTTP2
GHSA-c96f-x56v-gq3h CVE-2026-47219 HIGH 5 days ago
### Impact
Remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server.
The short version is that `lookup()` passes `req.met...
npm
No PRs yet
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
GHSA-g867-7843-wf8q CVE-2026-59935 HIGH 5 days ago
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a ...
pypi
No PRs yet
pypdf: Possible infinite loop for not terminated inline images
GHSA-5xf7-4p34-54qr CVE-2026-59936 HIGH 5 days ago
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a ...
pypi
No PRs yet
pypdf: Possible long runtimes for repeated malformed cross-reference entries
GHSA-55h5-xmcq-c37v CVE-2026-59937 MODERATE 5 days ago
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with repeat...
pypi
No PRs yet
pypdf: Possible large memory usage for wrong image dimensions
GHSA-5qjq-93h5-hrgp CVE-2026-59938 MODERATE 5 days ago
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the decla...
pypi
No PRs yet
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
GHSA-6g55-p6wh-862q CVE-2026-45623 HIGH 5 days ago
## Summary
PostCSS's `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `P...
npm
No PRs yet
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
GHSA-xh5m-36r6-47m3 CVE-2026-59933 HIGH 5 days ago
## Summary
PhpSpreadsheet's OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a max...
packagist
No PRs yet
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
GHSA-2mrg-gjxq-2gvr CVE-2026-59932 HIGH 5 days ago
## Summary
PhpSpreadsheet's Gnumeric reader reads attacker-supplied `.gnumeric` files into memory and, when the file starts with gzip magic bytes,...
packagist
No PRs yet
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
GHSA-6hq5-7373-42rg CVE-2026-59931 HIGH 5 days ago
### Summary
The domain whitelist introduced in PhpSpreadsheet 5.4.0 for the `WEBSERVICE()` formula function can be bypassed via HTTP redirect. The...
packagist
No PRs yet
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
GHSA-8fpg-xm3f-6cx3 CRITICAL 5 days ago
### Impact
`next-auth` (Auth.js) v5 applications that gate access by checking only for the **existence** of the `auth` object — the pattern shown ...
npm
No PRs yet
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-xmf8-cvqr-rfgj HIGH 5 days ago
## Summary
The exported `getToken()` helper (`next-auth/jwt` and `@auth/core/jwt`) can throw an uncaught exception when it reads a malformed `Auth...
npm
No PRs yet
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-7rqj-j65f-68wh CRITICAL 5 days ago
## Summary
The default email-address normalizer used by the email/magic-link sign-in flow validates the address **before** applying Unicode normal...
npm
No PRs yet