Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

13 advisories

Loading
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login Moderate
CVE-2026-54338 was published for jupyterhub (pip) Aug 25, 2026
mauriceng98 Credited to mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk Zyy0530 Zyy0530
Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) Moderate
CVE-2026-54625 was published for django-cms (pip) Aug 24, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and mauriceng98 7thParkk 7thParkk
mauriceng98 mauriceng98
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) High
CVE-2026-54623 was published for django-cms (pip) Aug 24, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
django CMS: Structure endpoint bypasses page-view permission Moderate
CVE-2026-54624 was published for django-cms (pip) Aug 20, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
django CMS: Clipboard copy IDOR discloses unauthorized plugin content Moderate
CVE-2026-54622 was published for django-cms (pip) Aug 20, 2026
Str1ckl4nd Credited to Str1ckl4nd, 7thParkk, and mauriceng98 7thParkk 7thParkk
mauriceng98 mauriceng98
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Socket.IO: Zero-attachment Memory Exhaustion High
CVE-2026-69185 was published for socket.io-parser (npm) Aug 3, 2026
aretekzs Credited to aretekzs, mauriceng98, Zyy0530, Str1ckl4nd, and 7thParkk mauriceng98 mauriceng98
Zyy0530 Zyy0530 Str1ckl4nd Str1ckl4nd 7thParkk 7thParkk
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling High
CVE-2026-59939 was published for httplib2 (pip) Jul 24, 2026
mauriceng98 Credited to mauriceng98
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser High
CVE-2026-49477 was published for soupsieve (pip) Jul 9, 2026
mauriceng98 Credited to mauriceng98
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists High
CVE-2026-49476 was published for soupsieve (pip) Jul 9, 2026
mauriceng98 Credited to mauriceng98
python-socketio: Binary attachment accumulation can cause denial of service High
CVE-2026-48804 was published for python-socketio (pip) Jun 26, 2026
mauriceng98 Credited to mauriceng98 and arpitjain099 arpitjain099 arpitjain099
python-engineio has unbound thread allocation that can cause denial of service High
CVE-2026-48802 was published for python-engineio (pip) Jun 26, 2026
mauriceng98 Credited to mauriceng98
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass High
CVE-2026-9675 was published for undici (npm) Jun 18, 2026
mauriceng98 Credited to mauriceng98, Str1ckl4nd, mcollina, and UlisesGascon Str1ckl4nd Str1ckl4nd
mcollina mcollina UlisesGascon UlisesGascon
ProTip! Advisories are also available from the GraphQL API