-
Notifications
You must be signed in to change notification settings - Fork 677
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-fgcw-684q-jj6r] huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
#8812
opened Jul 25, 2026 by
daemon
Loading…
[GHSA-83x9-8wvq-rrcp] The urwid web display backend (urwid/display/web.py)...
#8809
opened Jul 24, 2026 by
penguinolog
Loading…
[GHSA-vqqj-9cmv-hx43] Undertow is Vulnerable to HTTP Request/Response Smuggling
#8807
opened Jul 24, 2026 by
julianladisch
Loading…
[GHSA-3gv6-g396-9v4r] Undertow is Vulnerable to HTTP Request/Response Smuggling
#8806
opened Jul 24, 2026 by
julianladisch
Loading…
[GHSA-8v4x-mgvp-p658] Undertow is Vulnerable to HTTP Request/Response Smuggling
#8805
opened Jul 24, 2026 by
julianladisch
Loading…
[GHSA-6hcw-qqr8-pjj8] Apache Airflow: Authenticated users can bypass the
is_safe_url check
#8804
opened Jul 24, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-q2hg-643c-gw8h] Apache Airflow: RCE by race condition in example_xcom dag
#8803
opened Jul 24, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-2r5m-76wx-56gx] Apache Airflow Vulnerable to Deserialization of Untrusted Data
#8802
opened Jul 24, 2026 by
maheshwarivijaykumar
Loading…
[GHSA-2r2c-cx56-8933] JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
#8801
opened Jul 24, 2026 by
j-zygmunt
Loading…
[GHSA-47qp-hqvx-6r3f] JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
#8800
opened Jul 24, 2026 by
j-zygmunt
Loading…
[GHSA-8gh5-q362-whfc] Double free in Windows Kernel allows an authorized...
#8798
opened Jul 24, 2026 by
nikosecurity
Loading…
[GHSA-p7mv-53f2-4cwj] CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data
#8797
opened Jul 23, 2026 by
simonmorley
Loading…
[GHSA-pvx3-gm3c-gmpr] Denial of Service in Go-Ethereum
#8796
opened Jul 23, 2026 by
simonmorley
Loading…
[GHSA-gf47-qgg5-9g9q] Improper Validation of Certificate with Host Mismatch...
#8795
opened Jul 23, 2026 by
Ankush-Pathak
Contributor
Loading…
[GHSA-m4p7-r5rc-7g4j] pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
#8792
opened Jul 23, 2026 by
westonsteimel
Loading…
[GHSA-wmq2-jc9m-xp4m] Cross-site Scripting in in JRuby
#8791
opened Jul 23, 2026 by
yusuke-koyoshi
Loading…
[GHSA-xfqm-j7pc-xrfc] messageformat has a prototype pollution vulnerability
#8790
opened Jul 23, 2026 by
yusuke-koyoshi
Loading…
[GHSA-73jw-fp74-p77x] ws before 8.21.1 contains a memory exhaustion...
#8789
opened Jul 23, 2026 by
lpinca
Loading…
[GHSA-83x2-c529-vx4j] Missing Authorization vulnerability in Drupal Paragraphs...
#8788
opened Jul 23, 2026 by
valentijnscholten
Loading…
[GHSA-9hg7-4gq8-ppp9] randomUUID in Scala.js before 1.10.0 generates...
#8787
opened Jul 23, 2026 by
Malayke
Loading…
[GHSA-vvp9-h8p2-xwfc] Wasmtime: Memory leak in C API with
externref and anyref types
#8784
opened Jul 23, 2026 by
HsiangNianian
Loading…
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.