Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33,466 advisories

Loading
Guzzle: URI fragments disclosed in redirect Referer headers Moderate
GHSA-h95v-h523-3mw8 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Host-only cookie scope is not preserved Moderate
GHSA-wm3w-8rrp-j577 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-f283-ghqc-fg79 was published for guzzlehttp/guzzle (Composer) Jul 20, 2026
GrahamCampbell Credited to GrahamCampbell
jlgore Credited to jlgore
sec-reex Credited to sec-reex
Phillip9587 Credited to Phillip9587, efekrskl, UlisesGascon, and bjohansebas efekrskl efekrskl
UlisesGascon UlisesGascon bjohansebas bjohansebas
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
alanturing881 Credited to alanturing881
thientd Credited to thientd
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields Moderate
CVE-2026-59728 was published for @astrojs/rss (npm) Jul 20, 2026
alanturing881 Credited to alanturing881
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Serotav Credited to Serotav
Brubbish Credited to Brubbish
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service Moderate
CVE-2026-59203 was published for pillow (pip) Jul 20, 2026
jiagongzheng-stack Credited to jiagongzheng-stack
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() High
CVE-2026-59200 was published for Pillow (pip) Jul 20, 2026
redyank Credited to redyank
Serotav Credited to Serotav
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images Moderate
CVE-2026-59198 was published for Pillow (pip) Jul 20, 2026
Serotav Credited to Serotav
Serotav Credited to Serotav
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability High
CVE-2026-50651 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability Moderate
CVE-2026-50659 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability High
CVE-2026-50525 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability High
CVE-2026-50528 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability High
CVE-2026-50648 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability High
CVE-2026-50524 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability High
CVE-2026-47304 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability High
CVE-2026-47302 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
ProTip! Advisories are also available from the GraphQL API