-
Notifications
You must be signed in to change notification settings - Fork 751
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-2883-xcg3-v3hh] js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
#9489
opened Sep 14, 2026 by
lucianocoelho-28
Loading…
[GHSA-gxmc-34w7-fv72] Correct CWE for CVE-2022-39949
#9486
opened Sep 13, 2026 by
IgorKorkin
Loading…
[GHSA-h935-vxwx-xh2m] Update CVE-2025-59033 metadata
#9485
opened Sep 13, 2026 by
IgorKorkin
Loading…
Add missing fix commit reference to GHSA-5xxx-qhh7-9287
#9484
opened Sep 13, 2026 by
deathbringer-gd
Loading…
Add missing fix commit reference to GHSA-284h-m62q-gf8w
#9483
opened Sep 13, 2026 by
deathbringer-gd
Loading…
[GHSA-w67g-5rqw-f597] Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
#9482
opened Sep 13, 2026 by
waynercheung
Loading…
[GHSA-xm8c-hvjf-c5q9] npm-check-updates through 23.0.2, fixed in commit b554b84...
#9481
opened Sep 13, 2026 by
Monsieur-Nico
Loading…
[GHSA-325j-mg25-8q58] yayson: Prototype pollution in Store/LegacyStore deserialization
#9480
opened Sep 13, 2026 by
Monsieur-Nico
Loading…
[GHSA-p28p-j94q-pg32] http4k:
DigestAuthProvider.verify did not bind to request URI
#9477
opened Sep 12, 2026 by
Kxrma47
Loading…
[GHSA-hf57-cqmx-p4gr] OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
#9476
opened Sep 12, 2026 by
Kxrma47
Loading…
[GHSA-vwc7-r8mq-g2x9] adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite
#9475
opened Sep 12, 2026 by
Kxrma47
Loading…
[GHSA-2q42-4q24-7rgv] OpenAPI3 version value escapes
emitterOutputDir and overwrites YAML/JSON outside the output tree
#9474
opened Sep 12, 2026 by
Kxrma47
Loading…
[GHSA-w3rx-r6r6-pgpr] image-size: ICNS parser allows denial of service through an infinite loop
#9473
opened Sep 12, 2026 by
wojtekmaj
Loading…
[GHSA-5p2g-fcmc-qvqq] image-size: JXL and HEIF parsers allow denial of service through infinite loops
#9472
opened Sep 12, 2026 by
wojtekmaj
Loading…
[GHSA-4grx-2x9w-596c] Extend last_affected through rsa 0.10.0-rc.18
#9471
opened Sep 12, 2026 by
SebTardif
Loading…
[GHSA-c38w-74pg-36hr] Extend last_affected through rsa 0.10.0-rc.18
#9470
opened Sep 12, 2026 by
SebTardif
Loading…
[GHSA-992q-9gwp-7r79] ZITADEL: Auto-linking by email: IdP-side email verification is not checked
#9469
opened Sep 12, 2026 by
Kxrma47
Loading…
[GHSA-4qpv-39hg-f7fx] @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API
overrideAccess Omission
#9463
opened Sep 12, 2026 by
Kxrma47
Loading…
[GHSA-jf6q-chmf-3h3v] Add weasyprint 70.0 url_fetcher fix commit
#9462
opened Sep 12, 2026 by
SebTardif
Loading…
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.