Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS Moderate
CVE-2026-61784 was published for xhtml-purifier (npm) Sep 24, 2026
EchoTydes Credited to EchoTydes
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts Moderate
CVE-2026-55767 was published for guzzlehttp/guzzle (Composer) Jun 19, 2026
iliaal Credited to iliaal and EchoTydes EchoTydes EchoTydes
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse Low
CVE-2026-6733 was published for undici (npm) Jun 19, 2026
mcollina Credited to mcollina, UlisesGascon, and EchoTydes UlisesGascon UlisesGascon
EchoTydes EchoTydes
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` High
CVE-2026-54904 was published for concurrent-ruby (RubyGems) Jun 19, 2026
pranjalithakur Credited to pranjalithakur and EchoTydes EchoTydes EchoTydes
trace37labs Credited to trace37labs and EchoTydes EchoTydes EchoTydes
ProTip! Advisories are also available from the GraphQL API