Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34 advisories

Loading
arpitjain099 Credited to arpitjain099
Indico: Missing access check in legacy session export API Moderate
CVE-2026-107395 was published for indico (pip) Oct 8, 2026
arpitjain099 Credited to arpitjain099
music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort Moderate
CVE-2026-107389 was published for music-metadata (npm) Oct 8, 2026
bg0d-glitch Credited to bg0d-glitch, Zwique, offset, and arpitjain099 Zwique Zwique
offset offset arpitjain099 arpitjain099
svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences Moderate
CVE-2026-107381 was published for enshrined/svg-sanitize (Composer) Oct 8, 2026
arpitjain099 Credited to arpitjain099
Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics Moderate
CVE-2026-107218 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile High
CVE-2026-107219 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref Moderate
CVE-2026-107220 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
arpitjain099 Credited to arpitjain099
Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length or nil check Moderate
CVE-2026-107222 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
arpitjain099 Credited to arpitjain099
Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader Moderate
CVE-2026-107224 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml Moderate
CVE-2026-107225 was published for github.com/xuri/excelize/v2 (Go) Oct 7, 2026
arpitjain099 Credited to arpitjain099
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
arpitjain099 Credited to arpitjain099
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange Moderate
CVE-2026-102824 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path Low
CVE-2026-102825 was published for russh (Rust) Sep 30, 2026
arpitjain099 Credited to arpitjain099
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files Moderate
CVE-2026-92164 was published for streamlink (pip) Sep 24, 2026
arpitjain099 Credited to arpitjain099 and bastimeyer bastimeyer bastimeyer
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354) Moderate
GHSA-9rcc-pmj8-ffhr was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
arpitjain099 Credited to arpitjain099
Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write Critical
CVE-2026-75827 was published for getgrav/grav (Composer) Sep 17, 2026
arpitjain099 Credited to arpitjain099
arpitjain099 Credited to arpitjain099
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets Moderate
CVE-2026-88001 was published for open-webui (pip) Sep 9, 2026
arpitjain099 Credited to arpitjain099 and Classic298 Classic298 Classic298
multer vulnerable to Denial of Service via oversized array index in field names High
CVE-2026-82333 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev, UlisesGascon, and arpitjain099 UlisesGascon UlisesGascon
arpitjain099 arpitjain099
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed High
CVE-2026-83616 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc and arpitjain099 arpitjain099 arpitjain099
ProTip! Advisories are also available from the GraphQL API