An open index of dependabot pull requests across open source projects.

Security Advisories

Browse security advisories and track which Dependabot PRs address them.

34,982

Total Advisories

3,105

With Dependabot PRs

4,555

Critical Severity

12,244

High Severity

BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
EEF-CVE-2026-54890 GHSA-54pw-5645-jh86 CVE-2026-54890 HIGH about 5 hours ago
## Summary Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows For...
No PRs yet
Denial of service via exponential certificate policy tree growth in path validation
EEF-CVE-2026-59251 GHSA-622p-qfh6-c352 CVE-2026-59251 HIGH about 5 hours ago
## Summary Allocation of resources without limits in Erlang/OTP public\_key certificate path validation allows a remote unauthenticated attacker t...
No PRs yet
Megaco flex scanner buffer overflow via oversized property parm name
EEF-CVE-2026-59250 GHSA-7xgh-gmgf-q2g7 CVE-2026-59250 HIGH about 5 hours ago
## Summary Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's...
No PRs yet
TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
EEF-CVE-2026-58227 GHSA-r5jr-mq46-vmhw CVE-2026-58227 HIGH about 6 hours ago
## Summary The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS han...
No PRs yet
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-6vch-q96h-7gc3 HIGH 3 days ago
### Impact _What kind of vulnerability is it? Who is impacted?_ A network attacker who can reach an etcd TLS listener can open many TCP connection...
go
No PRs yet
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
GHSA-j6g5-3hh3-pgw8 CVE-2026-16796 HIGH 3 days ago
### Summary The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client th...
pypi
No PRs yet
etcd: Watch API authorization bypass via open-ended range requests
GHSA-xg4h-6gfc-h4m8 HIGH 3 days ago
### Impact _What kind of vulnerability is it? Who is impacted?_ A user granted READ permission on a single, exact key can use the Watch gRPC API w...
go
No PRs yet
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx CVE-2026-16756 HIGH 3 days ago
## Summary Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, pow...
cargo
No PRs yet
libp2p: yamux connection DoS via oversized data frame
GHSA-hmj8-5xmh-5573 HIGH 3 days ago
### Summary The yamux stream multiplexer in py-libp2p does not validate incoming DATA frame lengths against the receive window before reading the f...
pypi
No PRs yet
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-6xj8-qv9j-xcjq HIGH 3 days ago
### Summary Oh My Posh re-renders the resolved path string, which contains the raw folder names taken from the filesystem, through the Go `text/tem...
go
No PRs yet
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA-fp43-vj7g-pg92 HIGH 3 days ago
## 1. Forged combined-resource IDs `CombinedResourceInfo` accepts a path-derived ID without an authenticity check, inflates it without an output li...
maven
No PRs yet
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-gm3r-q2wp-hw87 HIGH 3 days ago
### Impact This impacts users of Shescape that have flag protection enabled, which is on by default, regardless of the API being used. An attacke...
npm
No PRs yet
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-29w2-fq35-v728 CVE-2026-16584 HIGH 3 days ago
## Summary The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services an...
pypi
No PRs yet
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-95cv-r8x4-vh75 HIGH 3 days ago
### Summary The `/api/fs/batch_rename` handler validates and authorizes only the requested source directory. It rejects path separators in `new_na...
go
No PRs yet
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-7ppr-r889-mcf2 HIGH 3 days ago
## Summary `http4s-blaze-server` aggregates the fragments of an incoming WebSocket message with no limit on total size or fragment count. A client...
maven
No PRs yet
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA-46q4-43ph-c6fr HIGH 3 days ago
### Summary blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Because trailer fields are attacker-controlled, a...
maven
No PRs yet
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-mhvj-jhpq-885v HIGH 3 days ago
### Summary Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`http/src/main/java/org/http4s/blaze/http/parser/...
maven
No PRs yet
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
GHSA-cmwh-g2h8-c222 HIGH 3 days ago
## Preface Poweradmin maps OIDC identities into local users through `oidc_user_links.oidc_subject` plus `provider_id`. In the MySQL schema, the OI...
packagist
No PRs yet
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
GHSA-rm67-g9ch-vxff HIGH 3 days ago
## Affected software - Product: Poweradmin (web front-end for PowerDNS) - Version tested: master, commit 7f28c3a97 (also reachable in the 4.x rele...
packagist
No PRs yet
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
GHSA-h4hf-v6w5-897x HIGH 3 days ago
### Summary The REST API user-update endpoint (`PUT/PATCH /api/v2/users/{id}` and the V1 equivalent) does not enforce two authorization rules that...
packagist
No PRs yet
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-mh99-v99m-4gvg CVE-2026-14257 HIGH 3 days ago
### Summary `expand()` bounds the *number* of results it produces (the `max` option, `100_000` by default) but not their *length*. By chaining man...
npm
No PRs yet
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GHSA-47w6-gwp4-w6vc HIGH 3 days ago
### Impact Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes. Worst they could do i...
pypi
No PRs yet
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-26gq-p25f-99cp HIGH 3 days ago
## Summary An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the en...
go
No PRs yet
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-g5vv-q72c-7j78 HIGH 3 days ago
### Summary `@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the re...
npm
No PRs yet
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
GHSA-g3hq-hphg-8fhh HIGH 3 days ago
### Summary pheditor's terminal feature restricts callers to an allowlist of commands (`TERMINAL_COMMANDS`) and rejects shell metacharacters. The ...
packagist
No PRs yet
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-94p4-4cq8-9g67 HIGH 3 days ago
## Summary The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `R...
pypi
No PRs yet
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-v42f-v8xc-j435 HIGH 3 days ago
### Summary Budibase's central outbound-fetch guard (`fetchWithBlacklist`) prevents SSRF/DNS-rebinding by resolving the target hostname, checking e...
npm
No PRs yet
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-pmpg-2mxq-6xwr HIGH 3 days ago
## Summary An end-user injection in Budibase's MongoDB datasource lets any BASIC app user bypass the builder's query-level access controls. Builde...
npm
No PRs yet
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-pvcr-8mvp-w8qr HIGH 3 days ago
### Summary The Budibase AI chat-link handoff flow (`GET/POST /api/chat-links/:instance/:token/handoff`) binds an **external chat identity** (Slac...
npm
No PRs yet
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
GHSA-2xgg-r2wc-c5r2 HIGH 3 days ago
### Summary **This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p (PostgreSQL SQL injection), reported in the same ori...
npm
No PRs yet
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-qw6m-8fw2-2v64 HIGH 3 days ago
## Summary Budibase's MongoDB query execution endpoint (`POST /api/v2/queries/:queryId`) is vulnerable to NoSQL injection through user-supplied qu...
npm
No PRs yet
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-hr66-5mqr-8mpx HIGH 3 days ago
#### Summary The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive...
npm
No PRs yet
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-xg5g-26x8-cvf4 HIGH 3 days ago
## Impact A builder-level user can make Budibase issue server-side HTTP requests to loopback or private-network targets by using DNS rebinding aga...
npm
No PRs yet
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xcx6-4f2g-hhgx HIGH 3 days ago
## Impact In Budibase v3.39.4, a regression in the authorization level for the S3 attachment upload endpoint allows any BASIC app user to obtain S...
npm
No PRs yet
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-ppr4-5f46-j9c6 HIGH 3 days ago
## Summary When creating a MongoDB datasource, Budibase passes the `tlsCertificateKeyFile` and `tlsCAFile` fields straight to the MongoDB driver as...
npm
No PRs yet
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-c8vc-7pv3-g98p HIGH 3 days ago
## Summary `POST /api/v2/email` on the account portal (`account.budibase.app`) starts an email-change workflow using a client-supplied `accountId`...
npm
No PRs yet
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-j9fc-w3mr-x6mv HIGH 3 days ago
### Summary Budibase `3.39.19` (commit `03fbabae4`) is affected by a privilege-escalation / missing-authorization flaw in the public role-assignme...
npm
No PRs yet
react-server-dom: Denial of Service in Server Functions
GHSA-wx67-qw84-cm4g CVE-2026-44907 HIGH 3 days ago
### Impact A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this coul...
npm
No PRs yet
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
GHSA-frvj-c5qp-xj4w CVE-2026-59221 HIGH 3 days ago
AI assistance was used to help inspect the code and prepare this report. ## Summary The fix for GHSA-r2wg-2mcr-66rv is incomplete in v0.9.6 and c...
pypi
No PRs yet
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
GHSA-j657-m4c4-24jq CVE-2026-59224 HIGH 3 days ago
## Summary The terminal proxy in `backend/open_webui/routers/terminals.py` forwards the Open WebUI user's identity to the upstream terminal server...
pypi
No PRs yet
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
GHSA-hq88-5x99-x3gf CVE-2026-55502 HIGH 3 days ago
## Summary Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to `Admin.Rea...
go
No PRs yet
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
GHSA-6v4j-43gg-vj32 CVE-2026-55404 HIGH 3 days ago
### Summary If the `--write-link`, `--write-url-link` or `--write-desktop-link` options are used with yt-dlp, it may produce output that can lead t...
pypi
No PRs yet
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
GHSA-74h3-cxq7-vc5q CVE-2026-59216 HIGH 3 days ago
## Summary An authenticated low-privilege user can execute arbitrary code-interpreter Python and tools inside **another** user's authenticated ses...
pypi
No PRs yet
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
GHSA-x2ff-v5v8-m75m CVE-2026-59714 HIGH 3 days ago
## Summary Any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by...
pypi
No PRs yet
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
GHSA-855v-hq7w-jmjw CVE-2026-59219 HIGH 3 days ago
## Summary With Redis configured, Open WebUI supports JWT revocation: `POST /api/v1/auths/signout` (per-token `jti`) and OIDC back-channel logout ...
pypi
No PRs yet
Open WebUI: Stored web worker XSS via Pyodide
GHSA-4r2p-27mh-5m22 CVE-2026-59214 HIGH 3 days ago
**Title:** Same-origin Pyodide code execution allows server-side RCE via a shared chat ### Summary Open WebUI runs client-side Python (Pyodide) i...
pypi
No PRs yet
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
GHSA-7835-87q9-rgvv CVE-2026-55607 HIGH 3 days ago
Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git di...
npm
No PRs yet
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
GHSA-v74w-7mr3-4qg3 HIGH 3 days ago
### Summary An attacker can cause Denial of Service by sending a specially crafted malicious XML payload (e.g., repeated `</` characters) to a Nett...
maven
No PRs yet
js-yaml: Exponential parsing time in flow collections leads to denial of service
GHSA-pm4m-ph32-ghv5 HIGH 3 days ago
### Summary Parsing a small YAML document can take exponential time. An application that calls `load()` or `loadAll()` on untrusted input can be hu...
npm
No PRs yet
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
GHSA-qwww-vcr4-c8h2 HIGH 3 days ago
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths. > [!NOTE] > This only affects your application if ...
npm
No PRs yet