-
Notifications
You must be signed in to change notification settings - Fork 687
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
fix version for nodebb on GHSA-9g4f-5rpg-4948
#8879
opened Jul 29, 2026 by
darakian
Contributor
Loading…
Correct brace-expansion ranges in GHSA-mh99-v99m-4gvg: fix was backported to 1.x, 2.x and 3.x
#8878
opened Jul 29, 2026 by
TechPro01
Loading…
Fix version ranges for GHSA-mh99-v99m-4gvg (brace-expansion)
#8877
opened Jul 29, 2026 by
andymai
Loading…
[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
#8876
opened Jul 29, 2026 by
serixscorpio
Loading…
[GHSA-mh99-v99m-4gvg] brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
#8875
opened Jul 29, 2026 by
oconnelc
Loading…
[GHSA-mh99-v99m-4gvg] brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
#8874
opened Jul 29, 2026 by
RMaksymczuk
Loading…
[GHSA-mh99-v99m-4gvg] brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
#8873
opened Jul 29, 2026 by
cd-rite
Loading…
[GHSA-wg5r-wc3x-39vc] OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
#8872
opened Jul 29, 2026 by
BarakSrour
Loading…
[GHSA-mh99-v99m-4gvg] brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
#8870
opened Jul 29, 2026 by
martin-tarjanyi
Loading…
[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
#8868
opened Jul 29, 2026 by
brookslybrand
Loading…
[GHSA-6wcc-39rp-hh9p] @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
#8867
opened Jul 29, 2026 by
BarakSrour
Loading…
[GHSA-crf3-v9rr-v7hj] A remote code execution (RCE) vulnerability exists in...
#8866
opened Jul 29, 2026 by
trosonke
Loading…
[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
#8865
opened Jul 29, 2026 by
stef-lang
Loading…
[GHSA-x3f8-2w95-hw4m] ChangeDetection.io before 0.54.7 allows arbitrary file read via unblocked XPath functions
#8864
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-m3px-q5gj-j9x7] kafka-python before 2.3.2 is vulnerable to memory exhaustion in the protocol parser
#8863
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-hqp4-2352-xf5r] Keras before 3.14.0 is vulnerable to path traversal during archive extraction
#8862
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-8cjm-8mp7-r2xf] Django 5.2 before 5.2.15 and 6.0 before 6.0.6 store cached responses with case-varied Cache-Control directives
#8861
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-2jcm-hq8r-84wx] kafka-python before 2.3.2 is vulnerable to denial of service via an unvalidated SCRAM iteration count
#8860
opened Jul 29, 2026 by
hahwul
Loading…
[GHSA-qwww-vcr4-c8h2] React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
#8858
opened Jul 29, 2026 by
erkro1
Loading…
[GHSA-crf3-v9rr-v7hj] Fix package mapping for CVE-2026-16723 Fastjson2 RCE
#8857
opened Jul 28, 2026 by
AnvithaCDhanekula
Loading…
[GHSA-52cp-r559-cp3m] js-yaml: YAML merge-key chains can force quadratic CPU consumption
#8856
opened Jul 28, 2026 by
SkyeCyclone
Loading…
[GHSA-2gh3-rmm4-6rq5] Crash due to uncontrolled recursion in protobuf crate
#8853
opened Jul 28, 2026 by
benholl94-cmyk
Loading…
[GHSA-4h8f-2wvx-gg5w] Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
#8850
opened Jul 28, 2026 by
tal-sealsecurity
Loading…
[GHSA-crf3-v9rr-v7hj] A remote code execution (RCE) vulnerability exists in...
#8849
opened Jul 28, 2026 by
dor-hayun
Loading…
Previous Next
ProTip!
Exclude everything labeled
bug with -label:bug.