Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,361 advisories

Loading
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS High
CVE-2026-40171 was published for @jupyter-notebook/help-extension (npm) Apr 30, 2026
dtrops Credited to dtrops, Carreau, Yann-P, krassowski, and jtpio Carreau Carreau
Yann-P Yann-P krassowski krassowski jtpio jtpio
Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest High
CVE-2026-41670 was published for admidio/admidio (Composer) Apr 29, 2026
offset Credited to offset
n8n has Open Redirect in MCP OAuth Consent Flow Moderate
CVE-2026-42230 was published for n8n (npm) Apr 29, 2026
ori-ron Credited to ori-ron
An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows... Moderate Unreviewed
CVE-2026-30346 was published Apr 27, 2026
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass) Moderate
GHSA-f3g8-9xv5-77gv was published for @saltcorn/server (npm) Apr 16, 2026
Grafana Loki Path Traversal - CVE-2021-36156 Bypass Moderate
CVE-2026-21726 was published for github.com/grafana/loki/v3 (Go) Apr 15, 2026
wooseokdotkim Credited to wooseokdotkim
@adonisjs/http-server has an Open Redirect vulnerability Moderate
CVE-2026-40255 was published for @adonisjs/core (npm) Apr 14, 2026
thetutlage Credited to thetutlage and TheAdamGalloway TheAdamGalloway TheAdamGalloway
Due to an Open Redirect vulnerability in SAP NetWeaver Application Server ABAP, an... Moderate Unreviewed
CVE-2026-34257 was published Apr 14, 2026
Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS Handler Low
GHSA-3jp4-mhh4-gcgr was published for kimai/kimai (Composer) Apr 14, 2026
morimori-dev Credited to morimori-dev
next-intl has an open redirect vulnerability Moderate
CVE-2026-40299 was published for next-intl (npm) Apr 10, 2026
joniumGit Credited to joniumGit
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be... Moderate Unreviewed
CVE-2026-22560 was published Apr 10, 2026
Apache Tomcat has an Open Redirect vulnerability Moderate
CVE-2026-25854 was published for org.apache.tomcat.embed:tomcat-embed-core (Maven) Apr 9, 2026
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects High
GHSA-pg8g-f2hf-x82m was published for openclaw (npm) Apr 9, 2026 withdrawn
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri High
GHSA-x3f4-v83f-7wp2 was published for github.com/authorizerdev/authorizer (Go) Apr 6, 2026
kodareef5 Credited to kodareef5
ProTip! Advisories are also available from the GraphQL API