Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
Improper handling of multiline messages in node-irc High
GHSA-52rh-5rpj-c3w6 was published for matrix-org-irc (npm) May 5, 2022
kurt-r2c sunnypatell
Credited to kurt-r2c and sunnypatell
Path Traversal in angular-http-server High
GHSA-vmhw-fhj6-m3g5 was published for angular-http-server (npm) May 31, 2019
sunnypatell
Credited to sunnypatell
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits High
CVE-2024-28101 was published for apollo-router (Rust) Mar 6, 2024
IvanGoncharov Geal
peakematt sunnypatell
Credited to IvanGoncharov, Geal, peakematt, and sunnypatell
*const c_void / ExternalPointer unsoundness leading to use-after-free High
CVE-2024-27934 was published for Deno (Rust) Mar 6, 2024
leesh3288 sunnypatell
Credited to leesh3288 and sunnypatell
Remote Code Execution by uploading a phar file using frontmatter High
CVE-2024-27923 was published for getgrav/grav (Composer) Mar 6, 2024
Universe1122 sunnypatell
Credited to Universe1122 and sunnypatell
Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials High
CVE-2024-28110 was published for github.com/cloudevents/sdk-go/v2 (Go) Mar 6, 2024
mattmoor tcnghia
sunnypatell
Credited to mattmoor, tcnghia, and sunnypatell
Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability High
CVE-2024-21386 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Feb 13, 2024
bbossola gillarramendi
sunnypatell
Credited to bbossola, gillarramendi, and sunnypatell
Shopware's session is persistent in Cache for 404 pages High
CVE-2024-27917 was published for shopware/platform (Composer) Mar 6, 2024
sunnypatell
Credited to sunnypatell
ProTip! Advisories are also available from the GraphQL API