Skip to content
View kodareef5's full-sized avatar

Block or report kodareef5

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kodareef5/README.md

Koda Reef

Security research and contributions to open-source software.

Projects   /   Work   /   Record notes

Activepieces Apache HTTP Server Astro authentik Authorizer BentoML Beszel c-ares Cilium CloudNativePG ComfyUI Composer Contour Coolify Cosign Dgraph Envoy External Secrets File Browser Fleet Flowise FreeScout Giskard go-witness Gotenberg Headlamp Kata Containers KubePi Nango NATS Server NGINX NGINX Ingress Controller Novu OAuth2 Proxy OneUptime OpenTelemetry Collector OpenTelemetry Go Pocket ID Poetry Prefect protoc-gen-validate pyLoad SiYuan Soft Serve SpaceWasm (NASA) Statamic systemd Tekton Pipelines Traefik TUF (Python) Vim Wekan witness ZITADEL

AVideo · bitbang-cli · bitbang-server · DOMPurify · gitoxide · GNOME GLib · go-git · gosaml2 · jsrsasign · libevent · libheif · libjpeg-turbo · libzip · lighttpd · phpseclib · pypdf · RustFS · simple-git · StableLib

73 projects · 70 published advisories · 12 merged patches

Work by project

Alphabetical by project; newest work first within each.

A   B   C   D   E   F   G   H   J   K   L   N   O   P   R   S   T   V   W   Z

A

CVE-2026-73081
GHSA-3pfv-m69p-5fv5
🟠 High
2026‑07‑17

A flow Code step’s name reached a shell-invoked bun build command without sufficient validation. An authenticated user able to create a flow could execute commands as the worker user before sandboxing began.

Versions, credits, and sources

GHSA-3pfv-m69p-5fv5

Maintainer advisory · Published 2026-07-17 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 4.0 8.7.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: p80n-sec (reporter), kodareef5 (reporter), Aviral2642 (reporter).

Maintainer package records

Package Affected Fixed
activepieces <= 0.79.4 0.80.0

CVE-2026-73081

CVE CNA source

CVE CNA: CVSS 4.0 8.7. CNA version record — activepieces: affected: < 0.80.0.

Coverage: HackerNoon · Aviral Srivastava.

Merged patch 2026-04-16
committed

Integer overflow guards in four core escaping functions

Credit and sources

Merged patch: Submitted by: Koda Reef. Checked 2026-09-06.

CVE-2026-41321
GHSA-88gm-j2wx-58h6
🔵 Low
2026‑04‑20

The Cloudflare image-binding transform checked only the initial remote-image URL and followed redirects. An open redirect on an allowed domain could bypass image-domain restrictions and trigger blind requests to destinations outside that allowlist.

Versions, credits, and sources

GHSA-88gm-j2wx-58h6

Maintainer advisory · Published 2026-04-20 · Checked 2026-09-06

Maintainer severity: 🔵 Low. Maintainer: CVSS 3.1 2.2.

GitHub global record · Indexed 2026-04-23.

Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.0; CVSS 3.1 2.2.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
@astrojs/cloudflare <= 13.1.6 13.1.10

GitHub global package records

Package Affected Fixed
@astrojs/cloudflare < 13.1.10 13.1.10

CVE-2026-41321

CVE CNA source

CVE CNA: CVSS 3.1 2.2. CNA version record — @astrojs/cloudflare: affected: < 13.1.10.

NVD record

Incomplete fix: GHSA-qpr4-c339-7vq8. Redirect controls added to other image paths were absent from the Cloudflare image-binding transform.

CVE-2026-41577
GHSA-4v4x-x5pr-8gp2
🟡 Moderate
2026‑05‑12

SAML assertion processing omitted time and audience conditions. An attacker holding a valid signed assertion could replay it after its signed expiry or use an assertion issued for a different service provider.

Vendor acknowledgement

SAML NameID truncation in CVE-2026-40165

Versions, credits, and sources

GHSA-4v4x-x5pr-8gp2

Maintainer advisory · Published 2026-05-12 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter), Android-Login-Analysis (reporter), AyushParkara (reporter).

Maintainer weaknesses: CWE-345.

Maintainer package records

Package Affected Fixed
authentik <= 2025.2.4 Not specified

CVE-2026-41577

CVE CNA source

CVE CNA: CVSS 4.0 6.9. CNA version record — authentik: affected: < 2025.12.5; affected: < 2026.2.3.

Vendor acknowledgement: Named on the vendor CVE page. Checked 2026-09-06.

CVE-2026-35511
GHSA-29rf-f4vv-pvq6
🔴 Critical
2026‑08‑13

OAuth login linked accounts by email without requiring the existing account to verify that address. An attacker who registered a victim’s email retained password access when the victim later signed in through an OAuth provider.

GHSA-x3f4-v83f-7wp2 🟠 High
2026‑04‑03

Several authentication endpoints attached tokens to caller-supplied redirect URLs without checking AllowedOrigins. An attacker could capture reset, magic-link, or authentication tokens after the victim followed an emailed link leading through the affected flow.

Versions, credits, and sources

GHSA-29rf-f4vv-pvq6

Maintainer advisory · Published 2026-08-13 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-08-14.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.7; CVSS 3.x 0.0.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-287.

Maintainer package records

Package Affected Fixed
github.com/authorizerdev/authorizer < 2.4.0-rc.16 2.4.0-rc.16

GitHub global package records

Package Affected Fixed
github.com/authorizerdev/authorizer < 0.0.0-20260807033110-66fe488fd2a4 0.0.0-20260807033110-66fe488fd2a4

CVE-2026-35511

Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check.

GHSA-x3f4-v83f-7wp2

Maintainer advisory · Published 2026-04-03 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-06.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.6; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-601.

Maintainer package records

Package Affected Fixed
github.com/authorizerdev/authorizer <= 2.0.0 Not specified

GitHub global package records

Package Affected Fixed
github.com/authorizerdev/authorizer < 0.0.0-20260329085140-6d9bef1aaba3 0.0.0-20260329085140-6d9bef1aaba3

CVE-2026-33766
GHSA-f359-r3pv-2phf
🟡 Moderate
2026‑03‑24

Image-download endpoints validated the starting URL but followed HTTP redirects without checking their destinations. A user with upload and edit permissions could redirect the server to internal services or reachable cloud metadata endpoints.

Versions, credits, and sources

GHSA-f359-r3pv-2phf

Maintainer advisory · Published 2026-03-24 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-03-26.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 5.3; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
wwbn/avideo <= 14.3 Not specified

GitHub global package records

Package Affected Fixed
wwbn/avideo <= 26.0 Not specified

CVE-2026-33766

CVE CNA source

CVE CNA: CVSS 4.0 5.3. CNA version record — AVideo: affected: <= 26.0.

NVD record

B

CVE-2026-35043
GHSA-fgv4-6jr3-jgfw
🔴 Critical
2026‑04‑02

Cloud deployment script generation inserted system_packages from bentofile.yaml into a shell command without quoting. An attacker-controlled package entry could execute commands during the BentoCloud build; an earlier local-path quoting fix missed this cloud-specific path.

Versions, credits, and sources

GHSA-fgv4-6jr3-jgfw

Maintainer advisory · Published 2026-04-02 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-03.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.8.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-78.

Maintainer package records

Package Affected Fixed
bentoml <= 1.4.37 1.4.38

GitHub global package records

Package Affected Fixed
bentoml <= 1.4.37 1.4.38

CVE-2026-35043

CVE CNA source

CVE CNA: CVSS 3.1 7.8. CNA version record — BentoML: affected: < 1.4.38.

NVD record

Incomplete fix: commit ce53491. The earlier quoting fix did not cover the cloud deployment setup script.

CVE-2026-40077
GHSA-5f5r-95pg-xrpm
🔵 Low
2026‑04‑09

Several hub endpoints checked authentication but not membership of the requested system. Cross-system container access required both a valid 15-character system ID and 12-character container ID; other affected endpoints could disclose system information or trigger SMART refreshes.

Versions, credits, and sources

GHSA-5f5r-95pg-xrpm

Maintainer advisory · Published 2026-04-09 · Checked 2026-09-06

Maintainer severity: 🔵 Low. Maintainer: CVSS 3.1 3.5.

GitHub global record · Indexed 2026-04-10.

Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.0; CVSS 3.1 3.5.

Contributors: marduc812 (reporter), kodareef5 (reporter), lakshayyverma (reporter).

Maintainer weaknesses: CWE-184.

Maintainer package records

Package Affected Fixed
github.com/henrygd/beszel <= 0.18.6 >= 0.18.7

GitHub global package records

Package Affected Fixed
github.com/henrygd/beszel <= 0.18.6 0.18.7

CVE-2026-40077

CVE CNA source

CVE CNA: CVSS 3.1 3.5. CNA version record — beszel: affected: < 0.18.7.

NVD record

Merged patch 2026-08-16
merged

Publish a running tmux session as a shareable URL

Merged patch 2026-08-01
merged

Reachable dnsmessage panic in mDNS response parsing (GO-2026-5942); golang.org/x/net bumped to v0.57.0

Credit and sources

Merged patch: PR authored by kodareef5 and merged. Checked 2026-09-06.

Ordinary open-source contribution.

Merged patch: PR merged. Checked 2026-09-06.

Merged patch 2026-08-15
merged

Add bitbang-metrics-dump and a build/test CI workflow

Credit and sources

Merged patch: PR authored by kodareef5 and merged. Checked 2026-09-06.

Ordinary open-source contribution.

C

Merged patch 2026-03-22
merged

Overflow checks in ares_buf_ensure_space()

Credit and sources

Merged patch: PR merged. Checked 2026-09-06.

Sources: Node.js release notes.

CVE-2026-41520
GHSA-gj49-89wh-h4gj
🟠 High
2026‑04‑22

Debug archives from WireGuard-enabled Cilium nodes included the node’s WireGuard private key. Anyone receiving an affected bugtool archive or sysdump obtained that key; remediation required rotating keys already shared in diagnostic bundles.

Versions, credits, and sources

GHSA-gj49-89wh-h4gj

Maintainer advisory · Published 2026-04-22 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.9.

GitHub global record · Indexed 2026-04-25.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.9.

Contributors: tklauser (remediation developer), kodareef5 (reporter).

Maintainer weaknesses: CWE-200, CWE-312.

Maintainer package records

Package Affected Fixed
cilium-bugtool < 1.17.15 1.17.15
cilium-bugtool >= 1.18.0, < 1.18.9 1.18.9
cilium-bugtool >= 1.19.0, < 1.19.3 1.19.3

GitHub global package records

Package Affected Fixed
github.com/cilium/cilium < 1.17.15 1.17.15
github.com/cilium/cilium >= 1.18.0, < 1.18.9 1.18.9
github.com/cilium/cilium >= 1.19.0, < 1.19.3 1.19.3

CVE-2026-41520

CVE CNA source

CVE CNA: CVSS 3.1 7.9. CNA version record — cilium: affected: < 1.17.15; affected: >= 1.18.0, < 1.18.9; affected: >= 1.19.0, < 1.19.3.

NVD record

Upstream acknowledgement 2026-05-07
committed

Recovery target validation

Upstream acknowledgement 2026-04-29
committed

Escaping in PostgreSQL configuration values

Credit and sources

Upstream acknowledgement: Suggested-by: Koda Reef. Checked 2026-09-06.

Upstream acknowledgement: Reported-by: Koda Reef. Checked 2026-09-06.

CVE-2026-56671
GHSA-pj59-g5vv-74q4
🟠 High
2026‑07‑15

The unauthenticated model-preview route accepted paths outside its model directory. Because responses were decoded and re-encoded as images, disclosure was limited to image-decodable files, with a separate oracle revealing whether other files existed.

Versions, credits, and sources

GHSA-pj59-g5vv-74q4

Maintainer advisory · Published 2026-07-15 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.5.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kartikganesh (finder), yd1ng (finder), sfwani (finder), icysun (finder), kodareef5 (finder), Tulgaaaaaaaa (finder).

Maintainer weaknesses: CWE-22.

Maintainer package records

Package Affected Fixed
ComfyUI < 0.28.0 0.28.0

CVE-2026-56671

CVE CNA source

CVE CNA: CVSS 3.1 7.5. CNA version record — ComfyUI: affected: < 0.28.0.

CVE-2026-40261
GHSA-gqw4-4w2p-838q
🟠 High
2026‑04‑14

Perforce package references and connection parameters entered shell commands without escaping. A repository supplying malicious Perforce source metadata could execute commands during source-preferred Composer installs, even when the Perforce client was not installed.

Versions, credits, and sources

GHSA-gqw4-4w2p-838q

Maintainer advisory · Published 2026-04-14 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.8.

GitHub global record · Indexed 2026-04-14.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.8.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-20, CWE-78.

Maintainer package records

Package Affected Fixed
composer/composer >= 2.3, < 2.9.6 2.9.6
composer/composer >= 1.0, < 2.2.27 2.2.27

GitHub global package records

Package Affected Fixed
composer/composer >= 2.3.0, < 2.9.6 2.9.6
composer/composer >= 1.0.0, < 2.2.27 2.2.27

CVE-2026-40261

CVE CNA source

CVE CNA: CVSS 3.1 8.8. CNA version record — composer: affected: >= 2.3.0, < 2.9.6; affected: >= 1.0.0, < 2.2.27.

NVD record

CVE-2026-41246
GHSA-x4mj-7f9g-29h4
🟠 High
2026‑04‑20

Cookie rewrite values entered generated Envoy Lua code without escaping. A user permitted to create or modify HTTPProxy resources could execute Lua in shared Envoy, read its xDS credentials, and potentially access other tenants’ TLS keys.

Versions, credits, and sources

GHSA-x4mj-7f9g-29h4

Maintainer advisory · Published 2026-04-20 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.1.

GitHub global record · Indexed 2026-04-24.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.1.

Contributors: b0b0haha (reporter), kodareef5 (reporter).

Maintainer weaknesses: CWE-94.

Maintainer package records

Package Affected Fixed
Unspecified >= v1.19.0 v1.33.4, v1.32.5, v1.31.6

GitHub global package records

Package Affected Fixed
github.com/projectcontour/contour >= 1.19.0, < 1.31.6 1.31.6
github.com/projectcontour/contour >= 1.32.0, < 1.32.5 1.32.5
github.com/projectcontour/contour >= 1.33.0, < 1.33.4 1.33.4

CVE-2026-41246

CVE CNA source

CVE CNA: CVSS 3.1 8.1. CNA version record — contour: affected: >= 1.33.0, < 1.33.4; affected: >= 1.32.0, < 1.32.5; affected: >= 1.19.0, < 1.31.6.

NVD record

Coverage: ZeroPath.

CVE-2026-34168
GHSA-mh8x-fppq-cp77
🟠 High
2026‑07‑02

Persistent-volume names entered shell commands without escaping during resource deletion. An authenticated API token holder able to configure storage could arrange command execution as root on managed servers when the affected resource was deleted.

Versions, credits, and sources

GHSA-mh8x-fppq-cp77

Maintainer advisory · Published 2026-07-02 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.8.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-78.

Maintainer package records

Package Affected Fixed
coollabsio/coolify <= 4.0.0-beta.470 4.0.0-beta.471

CVE-2026-34168

CVE CNA source

CVE CNA: CVSS 3.1 8.8. CNA version record — coolify: affected: < 4.0.0-beta.471.

Related work: CVE-2025-66213. The same shell-injection pattern occurred in other resource models; this is related work, not a demonstrated bypass of the identical patched path.

CVE-2026-39395
GHSA-w6c6-c85g-mmv6
🟡 Moderate
2026‑04‑06

Attestation verification mishandled predicate-type and payload-parsing failures across bundle formats. Without check-claims enabled, a valid signature over an unparsable payload or mismatched predicate type could still produce a successful verification result.

Versions, credits, and sources

GHSA-w6c6-c85g-mmv6

Maintainer advisory · Published 2026-04-06 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 4.3.

GitHub global record · Indexed 2026-04-08.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 4.3.

Contributors: kodareef5 (reporter).

Global weaknesses: CWE-754.

Maintainer package records

Package Affected Fixed
github.com/sigstore/cosign <= v3.0.5, <= v2.6.2 v3.0.6, v2.6.3

GitHub global package records

Package Affected Fixed
github.com/sigstore/cosign >= 3.0.0, < 3.0.6 3.0.6
github.com/sigstore/cosign < 2.6.3 2.6.3

CVE-2026-39395

CVE CNA source

CVE CNA: CVSS 3.1 4.3. CNA version record — cosign: affected: >= 3.0.0, < 3.0.6; affected: < 2.6.3.

NVD record

D

CVE-2026-34976
GHSA-p5rh-vmhp-gvcw
🔴 Critical
2026‑04‑02

The restoreTenant mutation lacked its authorization middleware entry. Unauthenticated callers reaching the admin GraphQL endpoint could overwrite a namespace from a supplied backup, probe local filesystem paths, or trigger requests through a controlled vault address.

Versions, credits, and sources

GHSA-p5rh-vmhp-gvcw

Maintainer advisory · Published 2026-04-02 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-02.

Global severity: 🔴 Critical. GitHub global: CVSS 4.0 0.0; CVSS 3.1 10.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-862.

Maintainer package records

Package Affected Fixed
github.com/dgraph-io/dgraph/v25 <=v25.3.0 v25.3.1, v24.1.6

GitHub global package records

Package Affected Fixed
github.com/dgraph-io/dgraph/v25 <= 25.3.0 25.3.1
github.com/dgraph-io/dgraph/v24 <= 24.0.5 Not specified
github.com/dgraph-io/dgraph <= 1.2.8 Not specified

CVE-2026-34976

CVE CNA source

CVE CNA: CVSS 3.1 10. CNA version record — dgraph: affected: < 25.3.1.

NVD record

Coverage: GBHackers · Cybersecurity News.

CVE-2026-41240
GHSA-h7mw-gpvr-xq4m
🟡 Moderate
2026‑04‑20

Function-based ADD_TAGS handling skipped FORBID_TAGS when the predicate returned true. Configurations combining those options could retain explicitly forbidden elements and their permitted attributes; the corresponding attribute-denylist path already had an earlier fix.

Merged patch · 2026-04-11 (merged) — Fix for CVE-2026-41240

Versions, credits, and sources

GHSA-h7mw-gpvr-xq4m

Maintainer advisory · Published 2026-04-20 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-22.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.0; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-183.

Global weaknesses: CWE-79, CWE-183.

Maintainer package records

Package Affected Fixed
dompurify <= 3.2.6 3.4.0

GitHub global package records

Package Affected Fixed
dompurify < 3.4.0 3.4.0

CVE-2026-41240

CVE CNA source

CVE CNA: CVSS 4.0 6. CNA version record — DOMPurify: affected: < 3.4.0.

NVD record

Incomplete fix: commit c361baa. The earlier FORBID_ATTR precedence fix did not cover the equivalent FORBID_TAGS case.

Merged patch: PR merged. Checked 2026-09-06.

Sources: CVE-2026-41240.

E

CVE-2026-73549
GHSA-jp5f-qr64-c9vw
🟡 Moderate
2026‑08‑26

Scoped IPv6 addresses could crash copyInternetAddressAndPort in ORIGINAL_DST or transparent-proxy paths. Exploitation depends on original-destination socket handling; the advisory reports source analysis, not a live reproduced exploit, and extends an earlier IPv6 fix.

Versions, credits, and sources

GHSA-jp5f-qr64-c9vw

Maintainer advisory · Published 2026-08-26 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 5.3.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter), antoniovleonti (remediation developer), phlax (coordinator), nezdolik (coordinator).

Maintainer weaknesses: CWE-754.

Maintainer package records

Package Affected Fixed
Envoy <1.40.0 1.39.1, 1.38.4, 1.37.6, 1.36.10

CVE-2026-73549

Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check.

Incomplete fix: CVE-2026-26310. The scoped-IPv6 fix in getAddressWithPort missed copyInternetAddressAndPort.

CVE-2026-34984
GHSA-r2pg-r6h7-crf3
🟠 High
2026‑04‑11

The template engine exposed getHostByName inside the controller process. A user able to author templated ExternalSecret resources could encode accessible secrets into DNS lookups; exploitation required outbound DNS from the controller, not direct egress from the attacker’s workload.

Versions, credits, and sources

GHSA-r2pg-r6h7-crf3

Maintainer advisory · Published 2026-04-11 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-13.

Global severity: 🟠 High. GitHub global: CVSS 4.0 7.1; CVSS 3.1 6.5.

Contributors: kodareef5 (reporter).

Global weaknesses: CWE-200.

Maintainer package records

Package Affected Fixed
github.com/external-secrets/external-secrets <2.3.0 2.3.0

GitHub global package records

Package Affected Fixed
github.com/external-secrets/external-secrets < 1.3.3-0.20260331202714-6800989bdc12 1.3.3-0.20260331202714-6800989bdc12
github.com/external-secrets/external-secrets >= 2.0.0, <= 2.2.0 Not specified

CVE-2026-34984

CVE CNA source

CVE CNA: CVSS 4.0 7.1. CNA version record — external-secrets: affected: < 2.3.0.

NVD record

F

CVE-2026-35604
GHSA-v9w4-gm2x-6rvf
🟠 High
2026‑04‑04

Public share access did not recheck the owner’s Share and Download permissions. Existing links remained downloadable after an administrator revoked those permissions, even though the same account could no longer create new shares.

Merged patch · 2026-04-04 (merged) — Share owner permissions checked on public share access

CVE-2026-35607
GHSA-7526-j432-6ppp
🟡 Moderate
2026‑04‑04

Proxy-authenticated accounts inherited default Execute permissions and configured commands, unlike ordinary signup accounts. Exposure required proxy authentication with command execution enabled and permissive administrator-configured defaults; the earlier signup fix did not cover auto-provisioning.

Merged patch · 2026-04-04 (merged) — Default permissions restricted for proxy-auth auto-provisioned users

CVE-2026-35606
GHSA-67cg-cpj7-qgc9
🟡 Moderate
2026‑04‑04

The resource endpoint returned text content and raw encoded bytes without checking Download permission. An authenticated user with downloads disabled could still read files within their authorized scope; directory and path authorization remained in effect.

Merged patch · 2026-04-04 (merged) — Download permission checked in the resource handler

CVE-2026-35605
GHSA-5q48-q4fm-g3m6
🟡 Moderate
2026‑04‑04

Access-rule matching used a string prefix without enforcing a directory boundary. An allow rule for one directory could also admit a sibling whose name shared that prefix; deny rules could over-match for the same reason.

Merged patch · 2026-04-04 (merged) — Directory boundaries enforced in access-rule path matching

Versions, credits, and sources

GHSA-v9w4-gm2x-6rvf

Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-08.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.2; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 <= 2.62.2 2.63.1

GitHub global package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 < 2.63.1 2.63.1

CVE-2026-35604

CVE CNA source

CVE CNA: CVSS 4.0 8.2. CNA version record — filebrowser: affected: < 2.63.1.

NVD record

Merged patch: PR merged. Checked 2026-09-06.

GHSA-7526-j432-6ppp

Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-08.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.1.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-269.

Maintainer package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 <= 2.62.2 2.63.1

GitHub global package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 < 2.63.1 2.63.1

CVE-2026-35607

CVE CNA source

CVE CNA: CVSS 3.1 8.1. CNA version record — filebrowser: affected: < 2.63.1.

NVD record

Incomplete fix: GHSA-x8jc-jvqm-pm3f. Signup permissions were restricted, but proxy-auth auto-provisioning kept the old defaults.

Merged patch: PR merged. Checked 2026-09-06.

GHSA-67cg-cpj7-qgc9

Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-08.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 5.3; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-862.

Maintainer package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 <= 2.62.2 2.63.1

GitHub global package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 < 2.63.1 2.63.1

CVE-2026-35606

CVE CNA source

CVE CNA: CVSS 4.0 5.3. CNA version record — filebrowser: affected: < 2.63.1.

NVD record

Merged patch: PR merged. Checked 2026-09-06.

GHSA-5q48-q4fm-g3m6

Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-08.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.3; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-22.

Maintainer package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 <= 2.62.2 2.63.1

GitHub global package records

Package Affected Fixed
github.com/filebrowser/filebrowser/v2 < 2.63.1 2.63.1

CVE-2026-35605

CVE CNA source

CVE CNA: CVSS 4.0 6.3. CNA version record — filebrowser: affected: < 2.63.1.

NVD record

Merged patch: PR merged. Checked 2026-09-06.

CVE-2026-41050
GHSA-765j-qfrp-hm3j
🔴 Critical
2026‑04‑30

Helm lookup and valuesFrom reads bypassed ServiceAccount impersonation and retained fleet-agent privileges. A tenant able to push to a monitored Git repository could read other namespaces’ secrets on targeted downstream clusters; single-tenant deployments were unaffected.

Versions, credits, and sources

GHSA-765j-qfrp-hm3j

Maintainer advisory · Published 2026-04-30 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: CVSS 3.1 9.9.

GitHub global record · Indexed 2026-05-07.

Global severity: 🔴 Critical. GitHub global: CVSS 4.0 0.0; CVSS 3.1 9.9.

Contributors: kodareef5 (reporter).

Global weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
github.com/rancher/fleet >=0.15.0,<0.15.1 0.15.1
github.com/rancher/fleet >=0.14.0,<0.14.5 0.14.5
github.com/rancher/fleet >=0.13.0,<0.13.10 0.13.10
github.com/rancher/fleet >=0.12.0,<0.12.14 0.12.14
github.com/rancher/fleet >=0.11.0,<0.11.13 0.11.13

GitHub global package records

Package Affected Fixed
github.com/rancher/fleet >= 0.15.0, < 0.15.1 0.15.1
github.com/rancher/fleet >= 0.14.0, < 0.14.5 0.14.5
github.com/rancher/fleet >= 0.13.0, < 0.13.10 0.13.10
github.com/rancher/fleet >= 0.12.0, < 0.12.14 0.12.14
github.com/rancher/fleet >= 0.11.0, < 0.11.13 0.11.13

CVE-2026-41050

CVE CNA source

CVE CNA: CVSS 3.1 9.9. CNA version record — Rancher: affected: 0.15.0 < 0.15.1; affected: 0.14.0 < 0.14.5; affected: 0.13.0 < 0.13.10; affected: 0.12.0 < 0.12.14; affected: 0.11.0 < 0.11.13.

NVD record

Coverage: GBHackers · CyberPress · Lyrie Research.

Lyrie Research: Page could not be retrieved during the September 6 review; retained from the earlier record.

GHSA-9cvr-5wv9-2gxr 🟠 High
2026‑08‑31

Cheerio, Playwright, and Puppeteer document loaders fetched URLs outside Flowise’s shared HTTP-security checks. A user able to configure these loaders could bypass the denylist and request internal destinations; the earlier HTTP-node fix did not cover them.

Versions, credits, and sources

GHSA-9cvr-5wv9-2gxr

Maintainer advisory · Published 2026-08-31 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 4.0 7.6.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
flowise <= 3.1.3 3.1.4
flowise-components <= 3.1.3 3.1.4

Incomplete fix: FlowiseAI/Flowise#5886. The HTTP-node SSRF fix did not cover document loaders.

CVE-2026-34443
GHSA-c9v3-4c59-x5q2
🟠 High
2026‑03‑30

The SSRF address check returned early for ordinary IP addresses, leaving configured CIDR blocks unenforced. An inbound email containing controlled attachment URLs could cause the server to request private-network destinations that the policy intended to block.

Versions, credits, and sources

GHSA-c9v3-4c59-x5q2

Maintainer advisory · Published 2026-03-30 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
freescout-helpdesk/freescout < 1.8.211 1.8.211

CVE-2026-34443

CVE CNA source

CVE CNA: CVSS 4.0 6.9. CNA version record — freescout: affected: < 1.8.211.

G

CVE-2026-34172
GHSA-frv4-x25r-588m
🟠 High
2026‑03‑26

ChatWorkflow.chat treated plain-string input as a Jinja2 template in an unsandboxed environment. Applications passing untrusted input directly to that method could expose command execution; values supplied through with_inputs did not take the vulnerable template-compilation path.

Versions, credits, and sources

GHSA-frv4-x25r-588m

Maintainer advisory · Published 2026-03-26 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-03-27.

Global severity: 🟠 High. GitHub global: CVSS 4.0 7.7; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-1336.

Maintainer package records

Package Affected Fixed
giskard-agents <= 0.3.3 0.3.4
giskard-agents >=1.0.1a1, <= 1.0.2a1 1.0.2b1

GitHub global package records

Package Affected Fixed
giskard-agents <= 0.3.3 0.3.4
giskard-agents >= 1.0.1a1, <= 1.0.2a1 1.0.2b1

CVE-2026-34172

CVE CNA source

CVE CNA: CVSS 4.0 7.7. CNA version record — giskard-oss: affected: < 0.3.4; affected: >= 1.0.1a1, < 1.0.2b1.

NVD record

CVE-2026-82254
GHSA-x494-mj8g-cj27
🟠 High
2026‑04‑25

Unchecked delta indexing and uncapped allocations allowed crafted Git pack data to crash consuming processes. A malicious remote could trigger a truncated-delta panic or excessive allocation during clone and fetch operations.

CVE-2026-82253
GHSA-p3hw-mv63-rf9w
🟠 High
2026‑04‑25

Incomplete submodule-name validation allowed paths to escape .git/modules, while inherited trust skipped ownership checks. Processing attacker-controlled submodule metadata could access unintended Git configuration and disclose credentials; package fix versions differ between published sources.

Versions, credits, and sources

GHSA-x494-mj8g-cj27

Maintainer advisory · Published 2026-04-25 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-05-05.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.7; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-248, CWE-770.

Maintainer package records

Package Affected Fixed
gix-pack <= 0.68.0 >= 0.69.0

GitHub global package records

Package Affected Fixed
gix-pack <= 0.68.0 0.69.0

CVE-2026-82254

CVE CNA source

CVE CNA: CVSS 4.0 8.7; CVSS 3.1 7.5. CNA version record — gitoxide: affected: 0 < 0.69.0; unaffected: 0.69.0.

GHSA-p3hw-mv63-rf9w

Maintainer advisory · Published 2026-04-25 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-05-05.

Global severity: 🟠 High. GitHub global: CVSS 4.0 7.5; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-22, CWE-200.

Maintainer package records

Package Affected Fixed
gix <= 0.72.0 >= 0.82.0
gix-validate <= 0.10.0 >= 0.11.1

GitHub global package records

Package Affected Fixed
gix < 0.83.0 0.83.0
gix-validate <= 0.10.0 0.11.1

CVE-2026-82253

CVE CNA source

CVE CNA: CVSS 4.0 8.7; CVSS 3.1 7.5. CNA version record — gitoxide: affected: 0 < 0.82.0; unaffected: 0.82.0. CNA version record — gitoxide: affected: 0 < 0.11.1; unaffected: 0.11.1.

Upstream acknowledgement 2026-04-29
committed

D-Bus message length integer arithmetic

Credit and sources

Upstream acknowledgement: Based on a report by Koda Reef. Checked 2026-09-06.

CVE-2026-71556
GHSA-hc8v-wwc9-vgxm
🟠 High
2026‑07‑30

Worktree writes checked path strings but followed existing symlinks. An attacker able to plant a symlink and trigger a write could escape the worktree or modify Git metadata, including configuration beneath .git.

GHSA-w5pp-99ch-qj29 🟡 Moderate
2026‑05‑18

Crafted pack, index, or loose-object data could cause panics or excessive resource use. Applications cloning, fetching, or opening untrusted repositories were exposed through a malicious remote or attacker-controlled files under .git/objects.

Report acknowledgement

CVE-2026-45571 report

Versions, credits, and sources

GHSA-hc8v-wwc9-vgxm

Maintainer advisory · Published 2026-07-30 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.1.

GitHub global record · Indexed 2026-08-07.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.1.

Contributors: kodareef5 (reporter), HughLewis20 (reporter).

Maintainer weaknesses: CWE-59.

Maintainer package records

Package Affected Fixed
github.com/go-git/go-git/v5 <= 5.19.1 5.19.2
github.com/go-git/go-git/v6 <= 6.0.0-alpha.4 6.0.0-alpha.5

GitHub global package records

Package Affected Fixed
github.com/go-git/go-git/v5 <= 5.19.1 5.19.2
github.com/go-git/go-git/v6 <= 6.0.0-alpha.4 6.0.0-alpha.5

CVE-2026-71556

CVE CNA source

CVE CNA: CVSS 3.1 7.1. CNA version record — go-git: affected: < 5.19.2; affected: >= 6.0.0-alpha.1, < 6.0.0-alpha.5.

GHSA-w5pp-99ch-qj29

Maintainer advisory · Published 2026-05-18 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.5.

GitHub global record · Indexed 2026-05-29.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 6.5.

Contributors: hiddeco (remediation developer), N0zoM1z0 (reporter), AyushParkara (reporter), kodareef5 (reporter).

Maintainer weaknesses: CWE-400.

Maintainer package records

Package Affected Fixed
github.com/go-git/go-git/v5 <=5.19.0 5.19.1
github.com/go-git/go-git/v6 <=6.0.0-alpha.3 6.0.0-alpha.4

GitHub global package records

Package Affected Fixed
github.com/go-git/go-git/v5 <= 5.19.0 5.19.1
github.com/go-git/go-git/v6 <= 6.0.0-alpha.3 6.0.0-alpha.4

Report acknowledgement: Thanks to @kodareef5, @AyushParkara and @N0zoM1z0 for reporting this to the go-git project in three separate reports. Checked 2026-09-06.

Named in the advisory body, not its structured credit list.

GHSA-6xq9-h39h-jc22 🔵 Low
2026‑07‑10

Policy verification appended the intermediate pool to itself instead of loading certificates from the trust bundle. Attestations requiring an intermediate CA failed verification; the failure was closed and did not accept unverified attestations.

Versions, credits, and sources

GHSA-6xq9-h39h-jc22

Maintainer advisory · Published 2026-07-10 · Checked 2026-09-06

Maintainer severity: 🔵 Low. Maintainer: no structured CVSS score.

CVSS: no structured score available from the checked sources.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter), jkjell (remediation developer).

Maintainer weaknesses: CWE-296.

Maintainer package records

Package Affected Fixed
github.com/in-toto/go-witness <= v0.9.1 >= v0.10.0

GHSA-vv4x-5gvr-chh8 🟡 Moderate
2026‑08‑19

The earlier LogoutRequest signature fix did not cover LogoutResponse validation. Applications using the affected POST-response validator could accept an unsigned SAML logout response; independent reports were combined in the published advisory.

Versions, credits, and sources

GHSA-vv4x-5gvr-chh8

Maintainer advisory · Published 2026-08-19 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 5.3.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter), tonghuaroot (reporter).

Maintainer weaknesses: CWE-347.

Maintainer package records

Package Affected Fixed
github.com/russellhaering/gosaml2 <= 0.11.0 v0.12.0

Incomplete fix: GHSA-pcgw-qcv5-h8ch. The LogoutRequest signature fix was not applied to LogoutResponse validation.

GHSA-qmwh-9m9c-h36m 🟠 High
2026‑04‑06

The ExifTool metadata filter was case-sensitive and omitted hard-link and symbolic-link tags. Callers of the metadata-write endpoint, unauthenticated by default, could write files or links outside intended paths, within the service’s filesystem permissions.

Versions, credits, and sources

GHSA-qmwh-9m9c-h36m

Maintainer advisory · Published 2026-04-06 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-07.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.8; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-73, CWE-178.

Maintainer package records

Package Affected Fixed
github.com/gotenberg/gotenberg/v8 <= 8.29.1 8.30.0

GitHub global package records

Package Affected Fixed
github.com/gotenberg/gotenberg/v8 <= 8.29.1 8.30.0

Incomplete fix: commit 043b158. The ExifTool blocklist remained case-sensitive and omitted hard-link and symlink tags.

H

Release acknowledgement 2026-05-07
released

Host-header validation in v0.42.0

Credit and sources

Release acknowledgement: thanks to Koda Reef for reporting the issue. Checked 2026-09-06.

J

Release acknowledgement 2026-04-13
released

DSA universal signature forgery from a missing FIPS 186-4 §4.7 boundary check, fixed in 11.1.2

Release acknowledgement 2026-04-13
released

ASN.1 parser infinite loop in getChildIdx, fixed in 11.1.2

Credit and sources

Release acknowledgement: reported by Koda Reef, Nicholas Carlini and @Kr0emer. Checked 2026-09-06.

Sources: Release archive.

Release acknowledgement: reported by Koda Reef. Checked 2026-09-06.

Sources: Release archive.

K

CVE-2026-41326
GHSA-q49m-57vm-c8cc
🔴 Critical
2026‑04‑22

CopyFile policy checked the destination path but not the symlink target supplied in request data. An untrusted host could redirect writes outside the shared directory and overwrite files inside the guest, including in confidential-container deployments.

Versions, credits, and sources

GHSA-q49m-57vm-c8cc

Maintainer advisory · Published 2026-04-22 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-05-04.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.2; CVSS 3.1 8.2.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: fitzthum (reporter), calonso-nv (finder), fikriwahab (finder), burgerdev (remediation developer), danmihai1 (remediation reviewer), jojimt (remediation reviewer), fidencio (remediation reviewer), kodareef5 (finder).

Global weaknesses: CWE-61.

Maintainer package records

Package Affected Fixed
Kata Containers v3.4.0 - v3.28.0 v3.29.0
Confidential Containers v0.9.0 - v0.19.0 v0.20.0

GitHub global package records

Package Affected Fixed
github.com/kata-containers/kata-containers < 0.0.0-20260422180503-1b9e49eb2763 0.0.0-20260422180503-1b9e49eb2763

CVE-2026-41326

CVE CNA source

CVE CNA: CVSS 4.0 8.2. CNA version record — kata-containers: affected: >= 3.4.0, < 3.29.0.

NVD record

CVE-2026-65956
GHSA-wjrh-4j52-c664
🟡 Moderate
2026‑08‑04

SSO configuration and connectivity-test endpoints were exposed outside the intended management boundary. Depending on authentication settings and deployment configuration, unauthenticated or low-privilege callers could alter SSO settings, potentially take over accounts, or trigger server-side requests.

Versions, credits, and sources

GHSA-wjrh-4j52-c664

Maintainer advisory · Published 2026-08-04 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-306.

Maintainer package records

Package Affected Fixed
github.com/1Panel-dev/kubepi <= 1.6.15 >= 2.0.0

CVE-2026-65956

CVE CNA source

CVE CNA: CVSS 4.0 10. CNA version record — KubePi: affected: < 2.0.0.

L

Release acknowledgement

HTTP header parsing restricted against request smuggling

Credit and sources

Release acknowledgement: Named in release notes. Checked 2026-09-06.

Sources: GHSA-q39v-w2g7-gr8j · CVE-2026-63382.

Named in the changelog; not counted as a structured advisory credit.

GHSA-9h96-c44j-jpq9 🟠 High
2026‑05‑19

A 32-bit stride calculation could wrap for large image widths, allocating an undersized plane. Processing a crafted HEIF or AVIF image could then overflow the heap, crashing or potentially compromising the consuming application.

Versions, credits, and sources

GHSA-9h96-c44j-jpq9

Maintainer advisory · Published 2026-05-19 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

CVSS: no structured score available from the checked sources.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-122, CWE-190.

Maintainer package records

Package Affected Fixed
libheif <= 1.19.8 v1.22.0

Report and fixes

Signed-overflow bounds checks across six JNI paths

Credit and sources

Report and fixes: Issue fixed across three commits linked with Fixes #877. Checked 2026-09-06.

Acknowledgement

Listed in THANKS

Credit and sources

Acknowledgement: kodareef5. Checked 2026-09-06.

Upstream acknowledgement 2026-05-04
committed

mod_maxminddb snprintf return-value bound

Credit and sources

Upstream acknowledgement: (thx kodareef5). Checked 2026-09-06.

N

CVE-2026-9316
GHSA-2j37-g5f6-h55p
🟠 High
2026‑08‑26

The proxy accepted a base-url-override header while its default network denylist was empty. Callers with a valid secret key or environment:proxy scope could direct authenticated proxy requests to private-network and metadata addresses.

Versions, credits, and sources

GHSA-2j37-g5f6-h55p

Maintainer advisory · Published 2026-08-26 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

CVSS: no structured score available from the checked sources.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: geo-chen (finder), KatrielMoses (finder), kodareef5 (finder), sajdakabir (finder), endscene665 (finder).

Maintainer weaknesses: CWE-918, CWE-1188.

Maintainer package records

Package Affected Fixed
NangoHQ/nango all builds prior to commit 83e0a0c commit 83e0a0c and later

CVE-2026-9316

Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check.

Release acknowledgement 2026-06-29
released

Non-CVE fixes acknowledged in v2.14.3 and v2.12.12

CVE-2026-58254
GHSA-p3j5-5hrq-p75h
🟡 Moderate
2026‑06‑29

Trace-destination permissions were not consistently checked for traffic arriving over leafnode connections. A leafnode operator could direct trace events to disallowed subjects, exposing routing and account metadata, and suppress normal message delivery.

CVE-2026-58214
GHSA-4g68-3pwx-5vfj
🟡 Moderate
2026‑06‑29

An internal-subject restriction omitted the MQTT delivery PUBREL family. Authenticated MQTT clients could bypass subscribe permissions and receive account-local QoS2 protocol metadata; the published impact did not include message payload disclosure.

CVE-2026-58250
GHSA-3g5q-cfh2-cq67
🟠 High
2026‑06‑29

Repeated pre-authentication leafnode INFO messages could leave handshake state unset and crash the server. Exploitation required access to a leafnode listener with compression enabled; disabling that compression mitigated the affected path.

Versions, credits, and sources

Release acknowledgement: Koda Reef in contributors. Checked 2026-09-06.

Sources: Release archive · v2.12.12.

GHSA-p3j5-5hrq-p75h

Maintainer advisory · Published 2026-06-29 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
github.com/nats-io/nats-server/v2 <= 2.14.2, <= 2.12.7 2.14.3, 2.12.8

CVE-2026-58254

CVE CNA source

CVE CNA: CVSS 4.0 5.3. CNA version record — nats-server: affected: < 2.12.8; affected: >= 2.14.0-RC.1, < 2.14.3.

Incomplete fix: CVE-2026-33249. Leafnode traffic still bypassed trace-destination permission checks.

GHSA-4g68-3pwx-5vfj

Maintainer advisory · Published 2026-06-29 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 4.3.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
github.com/nats-io/nats-server/v2 <= 2.14.2, <= 2.12.7 2.14.3, 2.12.8

CVE-2026-58214

CVE CNA source

CVE CNA: CVSS 3.1 4.3. CNA version record — nats-server: affected: < 2.12.12; affected: >= 2.14.0-RC.1, < 2.14.3.

Incomplete fix: CVE-2026-33217. The MQTT internal-subject restriction omitted the $MQTT.deliver.pubrel family.

GHSA-3g5q-cfh2-cq67

Maintainer advisory · Published 2026-06-29 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.6.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-476.

Maintainer package records

Package Affected Fixed
github.com/nats-io/nats-server/v2 <= 2.12.7, <= 2.11.16 2.12.8, 2.11.17

CVE-2026-58250

CVE CNA source

CVE CNA: CVSS 3.1 7.5. CNA version record — nats-server: affected: < 2.11.17; affected: >= 2.12.0-preview.1, < 2.12.8.

Incomplete fix: CVE-2026-29785 · CVE-2026-33218. The pre-auth leafnode crash remained after two earlier fixes.

Changelog acknowledgement

Constant-time secure_link hash comparison in 1.31.2

Credit and sources

Changelog acknowledgement: Thanks to kodareef5. Checked 2026-09-06.

CVE-2026-77180
Vendor/CVE record
🟠 High
2026‑09‑02

An authenticated user able to modify Kubernetes Ingress annotations could inject NGINX configuration. The vendor describes a control-plane issue requiring configuration access, not direct exploitation through data-plane traffic.

Versions, credits, and sources

CVE-2026-77180

F5 CNA credits kodareef5 as reporter.

CVE CNA source

CVE CNA: CVSS 4.0 8.7; CVSS 3.1 8.3. CNA version record — NGINX Ingress Controller: affected: 5.0.0 < 5.6.0; affected: 2026-lts-r1 < 2026-lts-r5.

F5 advisory

Standalone finding; excluded from GitHub advisory statistics.

GHSA-4x48-cgf9-q33f 🟠 High
2026‑04‑13

Conditions-filter webhooks bypassed the URL checks used by the HTTP Request step. A user with workflow-configuration access could issue server-side POST requests to internal endpoints and read responses through execution details.

Versions, credits, and sources

GHSA-4x48-cgf9-q33f

Maintainer advisory · Published 2026-04-13 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-14.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
@novu/api <= 2.6.1 >= 3.15.0
@novu/worker <= 2.6.1 >= 3.15.0

GitHub global package records

Package Affected Fixed
@novu/api < 3.15.0 3.15.0

O

CVE-2026-40574
GHSA-c5c4-8r6x-56w3
🟡 Moderate
2026‑04‑14

Email-domain validation accepted malformed claims containing multiple at signs, allowing an unintended domain suffix to match the allowlist. Exploitation required an identity provider capable of emitting such malformed claims; providers enforcing email syntax were unaffected.

Versions, credits, and sources

GHSA-c5c4-8r6x-56w3

Maintainer advisory · Published 2026-04-14 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.8.

GitHub global record · Indexed 2026-04-15.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 6.8.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-20.

Global weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
Unspecified < 7.15.2 > 7.15.1

GitHub global package records

Package Affected Fixed
github.com/oauth2-proxy/oauth2-proxy/v7 < 7.15.2 7.15.2

CVE-2026-40574

CVE CNA source

CVE CNA: CVSS 3.1 6.8. CNA version record — oauth2-proxy: affected: < 7.15.2.

NVD record

CVE-2026-34759
GHSA-6wc5-rhvj-cx7f
🔴 Critical
2026‑03‑30

Notification phone-number routes omitted service authorization and performed privileged operations. Using a project ID exposed by the status-page API, an unauthenticated caller could purchase Twilio numbers on the deployment’s account or release numbers used for alerts.

Versions, credits, and sources

GHSA-6wc5-rhvj-cx7f

Maintainer advisory · Published 2026-03-30 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-862.

Maintainer package records

Package Affected Fixed
oneuptime <= 7.0.0 10.0.40

CVE-2026-34759

CVE CNA source

CVE CNA: CVSS 4.0 9.2. CNA version record — oneuptime: affected: < 10.0.42.

CVE-2026-55701
GHSA-w5cv-pw74-4rxc
🟡 Moderate
2026‑06‑15

The GitHub receiver validated RequiredHeaders configuration but never enforced it on incoming requests. With the shared secret left at its empty default, callers could submit arbitrary webhook payloads and inject false CI/CD trace data.

Versions, credits, and sources

GHSA-w5cv-pw74-4rxc

Maintainer advisory · Published 2026-06-15 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-06-18.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.9; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver <= 0.150.0 >= 0.151.0

GitHub global package records

Package Affected Fixed
github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver <= 0.150.0 0.151.0

CVE-2026-55701

Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check.

NVD record

CVE-2026-39883
GHSA-hfvc-g4fc-pqhx
🟠 High
2026‑04‑08

Host-ID lookup invoked kenv by name instead of an absolute path. On affected BSD and Solaris paths, a local attacker controlling an earlier PATH directory could run a replacement executable inside the OpenTelemetry-using process.

Versions, credits, and sources

GHSA-hfvc-g4fc-pqhx

Maintainer advisory · Published 2026-04-08 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-08.

Global severity: 🟠 High. GitHub global: CVSS 4.0 7.3; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter), dmathieu (remediation developer).

Maintainer weaknesses: CWE-426.

Maintainer package records

Package Affected Fixed
go.opentelemetry.io/otel/sdk >= v1.15.0, <= 1.42.0 1.43.0

GitHub global package records

Package Affected Fixed
go.opentelemetry.io/otel/sdk >= 1.15.0, <= 1.42.0 1.43.0

CVE-2026-39883

CVE CNA source

CVE CNA: CVSS 4.0 7.3. CNA version record — opentelemetry-go: affected: >= 1.15.0, < 1.43.0.

NVD record

Incomplete fix: GHSA-9h8m-3fm2-qjrq. The earlier absolute-path fix covered ioreg but not kenv.

P

CVE-2026-40194
GHSA-r854-jrxh-36qx
🔵 Low
2026‑04‑10

SSH packet authentication compared HMACs with a variable-time operator instead of hash_equals. The timing difference is a defense-in-depth concern: authentication failure disconnects and rekeys the session, and the advisory does not establish a practical remote exploit.

Versions, credits, and sources

GHSA-r854-jrxh-36qx

Maintainer advisory · Published 2026-04-10 · Checked 2026-09-06

Maintainer severity: 🔵 Low. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-10.

Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.0; CVSS 3.1 3.7.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-208.

Maintainer package records

Package Affected Fixed
phpseclib/phpseclib >=3.0.0,<=3.0.50 3.0.51
phpseclib/phpseclib >=2.0.0,<=2.0.52 2.0.53
phpseclib/phpseclib >=0.1.1,<=1.0.27 1.0.28

GitHub global package records

Package Affected Fixed
phpseclib/phpseclib >= 2.0.0, < 2.0.53 2.0.53
phpseclib/phpseclib >= 3.0.0, < 3.0.51 3.0.51
phpseclib/phpseclib >= 0.1.1, < 1.0.28 1.0.28

CVE-2026-40194

CVE CNA source

CVE CNA: CVSS 3.1 3.7. CNA version record — phpseclib: affected: >= 0.1.1, < 1.0.28; affected: >= 2.0.0, < 2.0.53; affected: >= 3.0.0, < 3.0.51.

NVD record

CVE-2026-43983
GHSA-w6p7-2fxx-4f44
🟠 High
2026‑04‑26

Refreshing an OIDC token did not recheck account disabling, authorization revocation, or group restrictions. Holders of an existing refresh token and the required client credentials could continue obtaining tokens after administrators removed access.

GHSA-hp74-gm6m-2qm5 🟡 Moderate
2026‑04‑26

The reauthentication fallback checked access-token freshness and a session cookie, but not how login occurred. A stolen one-time access token could therefore satisfy step-up requirements and obtain tokens for protected OIDC clients.

Versions, credits, and sources

GHSA-w6p7-2fxx-4f44

Maintainer advisory · Published 2026-04-26 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-07-28.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.5; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-285, CWE-613.

Maintainer package records

Package Affected Fixed
github.com/pocket-id/pocket-id/backend <= 2.5.0 2.6.0

GitHub global package records

Package Affected Fixed
github.com/pocket-id/pocket-id/backend < 0.0.0-20260419162744-978ac87deffe 0.0.0-20260419162744-978ac87deffe

CVE-2026-43983

CVE CNA source

CVE CNA: CVSS 4.0 8.5. CNA version record — pocket-id: affected: < 2.6.0.

NVD record

GHSA-hp74-gm6m-2qm5

Maintainer advisory · Published 2026-04-26 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-07-28.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.0; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-287.

Maintainer package records

Package Affected Fixed
github.com/pocket-id/pocket-id/backend <= 2.5.0 2.6.0

GitHub global package records

Package Affected Fixed
github.com/pocket-id/pocket-id/backend < 0.0.0-20260419162744-978ac87deffe 0.0.0-20260419162744-978ac87deffe

CVE-2026-41140
GHSA-73h3-mf4w-8647
🔵 Low
2026‑04‑18

On Python versions lacking tarfile’s data filter, Poetry extracted source distributions without traversal protection. Crafted archive members could escape the extraction directory during dependency resolution; the advisory rates this low because package build backends already execute code.

Versions, credits, and sources

GHSA-73h3-mf4w-8647

Maintainer advisory · Published 2026-04-18 · Checked 2026-09-06

Maintainer severity: 🔵 Low. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-22.

Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.6; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter), radoering (remediation reviewer).

Maintainer weaknesses: CWE-22.

Maintainer package records

Package Affected Fixed
poetry <= 2.3.3 2.3.4

GitHub global package records

Package Affected Fixed
poetry < 2.3.4 2.3.4

CVE-2026-41140

CVE CNA source

CVE CNA: CVSS 4.0 0.6. CNA version record — poetry: affected: < 2.3.4.

NVD record

CVE-2026-5366
Vendor/CVE record
🔴 Critical
2026‑06‑20

Deployment pull steps accepted unsafe Git commit and sparse-checkout directory arguments. A user permitted to create deployments could execute commands on the worker host, with additional exposure where work pools were shared.

Versions, credits, and sources

CVE-2026-5366

Reported and CVE-assigned through huntr.

CVE CNA source

CVE CNA: CVSS 3.0 9.9. CNA version record — prefecthq/prefect: affected: unspecified ≤ latest.

huntr report

upstream fix

Standalone finding; excluded from GitHub advisory statistics.

Merged patch 2026-05-27
merged

Malformed UTF-8 length validation bypass

Credit and sources

Merged patch: PR merged. Checked 2026-09-06.

CVE-2026-35459
GHSA-7gvf-3w72-p2pg
🟠 High
2026‑04‑02

The downloader validated its initial destination but followed redirects without rechecking targets. An authenticated user with ADD permission could fetch internal services or reachable metadata endpoints; returned data was written into the download storage folder.

CVE-2026-35464
GHSA-4744-96p5-mp2j
🔴 Critical
2026‑04‑02

Non-admin users with SETTINGS and ADD permissions could point storage_folder at Flask’s session store and download a crafted serialized session. A subsequent request using that session cookie could execute code in the web process.

Versions, credits, and sources

GHSA-7gvf-3w72-p2pg

Maintainer advisory · Published 2026-04-02 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-04.

Global severity: 🔴 Critical. GitHub global: CVSS 4.0 9.3; CVSS 3.x 0.0.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
pyload-ng <= 0.5.0b3 pyload-ng 0.5.0b3.dev97

GitHub global package records

Package Affected Fixed
pyload-ng <= 0.5.0b3.dev96 Not specified

CVE-2026-35459

CVE CNA source

CVE CNA: CVSS 4.0 9.3. CNA version record — pyload: affected: <= 0.5.0b3.dev96.

NVD record

Incomplete fix: CVE-2026-33992. Redirect targets were not revalidated by the SSRF filter.

Coverage: SANS AtRisk XXVI-14.

GHSA-4744-96p5-mp2j

Maintainer advisory · Published 2026-04-02 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-04.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.5.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-502, CWE-863.

Maintainer package records

Package Affected Fixed
pyload-ng <= 0.5.0b3 Not specified

GitHub global package records

Package Affected Fixed
pyload-ng <= 0.5.0b3 Not specified

CVE-2026-35464

CVE CNA source

CVE CNA: CVSS 3.1 7.5. CNA version record — pyload: affected: <= 0.5.0b3.dev96.

NVD record

Incomplete fix: CVE-2026-33509. storage_folder remained writable into the Flask session store.

CVE-2026-40260
GHSA-3crg-w4f6-42mx
🟡 Moderate
2026‑04‑10

PDF XMP parsing processed entity declarations without effective expansion limits. A crafted document could exhaust application memory, but merely opening a PDF was insufficient unless the consuming application also parsed its XMP metadata.

Versions, credits, and sources

GHSA-3crg-w4f6-42mx

Maintainer advisory · Published 2026-04-10 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-10.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.9; CVSS 3.1 5.3.

Contributors: kodareef5 (reporter), stefan6419846 (analyst).

Maintainer weaknesses: CWE-776.

Maintainer package records

Package Affected Fixed
pypdf < 6.10.0 >= 6.10.0

GitHub global package records

Package Affected Fixed
pypdf < 6.10.0 6.10.0

CVE-2026-40260

CVE CNA source

CVE CNA: CVSS 4.0 6.9. CNA version record — pypdf: affected: < 6.10.0.

NVD record

R

GHSA-mm2q-qcmx-gw4w 🟠 High
2026‑04‑25

Service-account listing checked the wrong administrative action, and updates omitted an ownership check. A user granted admin:UpdateServiceAccount could enumerate other users’ service-account keys, including root-owned keys, and rotate their secrets.

CVE-2026-40937
GHSA-pfcq-4gjr-6gjm
🟡 Moderate
2026‑04‑22

Notification-target handlers authenticated callers but omitted administrator authorization. A read-only user could overwrite known targets, redirect bucket events to a controlled webhook, and make the server probe internal endpoints through target health checks.

Versions, credits, and sources

GHSA-mm2q-qcmx-gw4w

Maintainer advisory · Published 2026-04-25 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-05-05.

Global severity: 🟠 High. GitHub global: CVSS 4.0 7.4; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-863.

Maintainer package records

Package Affected Fixed
rustfs <= 1.0.0-alpha.91 1.0.0-alpha.98

GitHub global package records

Package Affected Fixed
rustfs <= 1.0.0-alpha.91 1.0.0-alpha.98

GHSA-pfcq-4gjr-6gjm

Maintainer advisory · Published 2026-04-22 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-22.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.3.

The maintainer and global severity labels differ; this page uses the maintainer’s label.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-862.

Maintainer package records

Package Affected Fixed
rustfs <= 1.0.0-alpha.93 1.0.0-alpha.94

GitHub global package records

Package Affected Fixed
rustfs <= 0.0.2 Not specified

CVE-2026-40937

CVE CNA source

CVE CNA: CVSS 3.1 8.3. CNA version record — rustfs: affected: < 1.0.0-alpha.94.

NVD record

S

Changelog acknowledgement

Blocked GIT_CONFIG_COUNT environment variables and --template / merge configuration keys in 3.36.0

Credit and sources

Changelog acknowledgement: Thanks to @kodareef5 for identifying the need to block GIT_CONFIG_COUNT environment variables and --template / merge related config. Checked 2026-09-06.

CVE-2026-40107
GHSA-w95v-4h65-j455
🟠 High
2026‑04‑09

Mermaid rendering allowed embedded image URLs to survive sanitization. Opening a crafted note triggered requests; on Windows, a network-share URL could additionally expose the user’s NTLMv2 challenge-response hash through automatic authentication.

Versions, credits, and sources

GHSA-w95v-4h65-j455

Maintainer advisory · Published 2026-04-09 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-10.

Global severity: 🟠 High. GitHub global: CVSS 4.0 8.7; CVSS 3.x 0.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
siyuan <= 3.6.3 v3.6.4

GitHub global package records

Package Affected Fixed
github.com/siyuan-note/siyuan/kernel < 0.0.0-20260407035653-2f416e5253f1 0.0.0-20260407035653-2f416e5253f1

CVE-2026-40107

CVE CNA source

CVE CNA: CVSS 4.0 8.7. CNA version record — siyuan: affected: < 3.6.4.

NVD record

GHSA-vpj5-m56f-8h3f 🟡 Moderate
2026‑07‑30

Repository imports and recurring mirror syncs accepted remote URLs without the existing SSRF validation. A user with a registered SSH key could make the server request loopback, private-network, or metadata endpoints.

Versions, credits, and sources

GHSA-vpj5-m56f-8h3f

Maintainer advisory · Published 2026-07-30 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.4.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: tonghuaroot (reporter), 456789TZ (reporter), kodareef5 (reporter), thientd (reporter).

Maintainer weaknesses: CWE-918.

Maintainer package records

Package Affected Fixed
github.com/charmbracelet/soft-serve >= 0.6.0 0.12.0

GHSA-fvwj-92vj-fg8c 🔴 Critical
2026‑08‑05

A result-typed WebAssembly if without an else could pass validation despite producing no value. Repeated constructs desynchronized the operand stack, exposing host-memory values and allowing writes into another module’s linear memory.

GHSA-r5f5-cv78-6qv8 🟠 High
2026‑07‑27

The C host-call trampoline pushed a result even for functions declared void. Guest modules invoking these functions could corrupt operand-stack state; repeated calls advanced the stack beyond its allocation and crashed the process.

Versions, credits, and sources

GHSA-fvwj-92vj-fg8c

Maintainer advisory · Published 2026-08-05 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: CVSS 3.1 9.0.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-20.

Maintainer package records

Package Affected Fixed
spacewasm 0.4.0 0.5.2

GHSA-r5f5-cv78-6qv8

Maintainer advisory · Published 2026-07-27 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.2.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-670.

Maintainer package records

Package Affected Fixed
spacewasm_c_api 0.4.0 0.4.3

GHSA-x3ff-w252-2g7j 🟡 Moderate
2026‑03‑30

Ed25519 verification did not enforce the scalar range required for a canonical signature. Anyone holding a valid signature could derive a second valid encoding without the signing key, affecting applications that rely on signature uniqueness.

Versions, credits, and sources

GHSA-x3ff-w252-2g7j

Maintainer advisory · Published 2026-03-30 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score.

GitHub global record · Indexed 2026-04-01.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 5.3.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-347.

Maintainer package records

Package Affected Fixed
@stablelib/ed25519 <= 2.0.2 Not specified

GitHub global package records

Package Affected Fixed
@stablelib/ed25519 <= 2.0.2 Not specified

CVE-2026-41175
GHSA-4jjr-vmv7-wh4w
🟠 High
2026‑04‑15

Query values could resolve into destructive method calls. Minimal Control Panel permissions could enable data deletion; unauthenticated exposure required REST or GraphQL to be explicitly enabled without authentication and with the affected resources exposed.

Versions, credits, and sources

GHSA-4jjr-vmv7-wh4w

Maintainer advisory · Published 2026-04-15 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.1.

GitHub global record · Indexed 2026-04-16.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.1.

Contributors: joshuaalwin (reporter), kodareef5 (reporter).

Maintainer weaknesses: CWE-470.

Maintainer package records

Package Affected Fixed
statamic/cms <5.73.20, <6.13.0 5.73.20, 6.13.0

GitHub global package records

Package Affected Fixed
statamic/cms < 5.73.20 5.73.20
statamic/cms >= 6.0.0-alpha.1, < 6.13.0 6.13.0

CVE-2026-41175

CVE CNA source

CVE CNA: CVSS 3.1 8.1. CNA version record — cms: affected: < 5.73.20; affected: >= 6.0.0-alpha.1, < 6.13.0.

NVD record

GHSA-m8q3-73v4-wvg7 🟡 Moderate
2026‑08‑10

A malicious iSCSI or USB device could inject udev properties through unsanitized SCSI identifiers. The earlier serial-number fix missed equivalent fields, allowing device data to request a systemd unit running as root.

Versions, credits, and sources

GHSA-m8q3-73v4-wvg7

Maintainer advisory · Published 2026-08-10 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.4.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-74.

Maintainer package records

Package Affected Fixed
udev < 261 261 260.2 259.6 258.8

Incomplete fix: GHSA-vpfq-8p5f-jcqx. Validation covered ID_SCSI_SERIAL but not equivalent fields from the same VPD data.

T

CVE-2026-40161
GHSA-wjxp-xrpv-xpff
🟠 High
2026‑04‑21

Git resolver API mode combined a user-supplied server URL with the system-configured Git token when no token parameter was supplied. A tenant able to create TaskRuns could redirect that authenticated request to a controlled server.

CVE-2026-40923
GHSA-rx35-6rhx-7858
🟡 Moderate
2026‑04‑21

Volume-mount restrictions compared raw paths without normalization. A Task or TaskRun author could use parent-directory components to mount over protected Tekton locations, allowing replacement of internal results or step scripts.

CVE-2026-40938
GHSA-94jr-7pqp-xhcq
🟠 High
2026‑04‑21

The Git resolver passed revision values to git fetch as arguments without separating options. A tenant able to submit ResolutionRequests and predict a pod-local repository path could execute commands and access the resolver’s cluster-wide Secret permissions.

Downstream fixes — Downstream propagation of CVE-2026-40938 across OpenShift product lines

Versions, credits, and sources

GHSA-wjxp-xrpv-xpff

Maintainer advisory · Published 2026-04-21 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.7.

GitHub global record · Indexed 2026-04-21.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.7.

Contributors: kodareef5 (reporter), vdemeester (remediation developer).

Maintainer weaknesses: CWE-201.

Maintainer package records

Package Affected Fixed
github.com/tektoncd/pipeline >= 1.0.0, <= 1.10.0 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1

GitHub global package records

Package Affected Fixed
github.com/tektoncd/pipeline >= 1.0.0, < 1.0.2 1.0.2
github.com/tektoncd/pipeline >= 1.2.0, < 1.3.4 1.3.4
github.com/tektoncd/pipeline >= 1.4.0, < 1.6.2 1.6.2
github.com/tektoncd/pipeline >= 1.7.0, < 1.9.3 1.9.3
github.com/tektoncd/pipeline >= 1.10.0, < 1.11.1 1.11.1

CVE-2026-40161

CVE CNA source

CVE CNA: CVSS 3.1 7.7. CNA version record — pipeline: affected: >= 1.0.0, < 1.0.2; affected: >= 1.2.0, < 1.3.4; affected: >= 1.4.0, < 1.6.2; affected: >= 1.7.0, < 1.9.3; affected: >= 1.10.0, < 1.11.1.

NVD record

GHSA-rx35-6rhx-7858

Maintainer advisory · Published 2026-04-21 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 5.4.

GitHub global record · Indexed 2026-04-21.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 5.4.

Contributors: kodareef5 (reporter), vdemeester (remediation developer), aThorp96 (remediation reviewer).

Maintainer weaknesses: CWE-22.

Maintainer package records

Package Affected Fixed
github.com/tektoncd/pipeline <= 1.10.0 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1

GitHub global package records

Package Affected Fixed
github.com/tektoncd/pipeline >= 1.10.0, < 1.11.1 1.11.1
github.com/tektoncd/pipeline >= 1.7.0, < 1.9.3 1.9.3
github.com/tektoncd/pipeline >= 1.4.0, < 1.6.2 1.6.2
github.com/tektoncd/pipeline >= 1.2.0, < 1.3.4 1.3.4
github.com/tektoncd/pipeline >= 1.0.0, < 1.0.2 1.0.2

CVE-2026-40923

CVE CNA source

CVE CNA: CVSS 3.1 5.4. CNA version record — pipeline: affected: >= 1.0.0, < 1.0.2; affected: >= 1.2.0, < 1.3.4; affected: >= 1.4.0, < 1.6.2; affected: >= 1.7.0, < 1.9.3; affected: >= 1.10.0, < 1.11.1.

NVD record

GHSA-94jr-7pqp-xhcq

Maintainer advisory · Published 2026-04-21 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.5.

GitHub global record · Indexed 2026-04-21.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.5.

Contributors: offset (reporter), vdemeester (remediation developer), kodareef5 (finder).

Maintainer weaknesses: CWE-88.

Maintainer package records

Package Affected Fixed
github.com/tektoncd/pipeline >= 1.0.0 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1

GitHub global package records

Package Affected Fixed
github.com/tektoncd/pipeline >= 1.10.0, < 1.11.1 1.11.1
github.com/tektoncd/pipeline >= 1.7.0, < 1.9.3 1.9.3
github.com/tektoncd/pipeline >= 1.4.0, < 1.6.2 1.6.2
github.com/tektoncd/pipeline >= 1.2.0, < 1.3.4 1.3.4
github.com/tektoncd/pipeline >= 1.0.0, < 1.0.2 1.0.2

CVE-2026-40938

CVE CNA source

CVE CNA: CVSS 3.1 7.5. CNA version record — pipeline: affected: >= 1.0.0, < 1.0.2; affected: >= 1.2.0, < 1.3.4; affected: >= 1.4.0, < 1.6.2; affected: >= 1.7.0, < 1.9.3; affected: >= 1.10.0, < 1.11.1.

NVD record

Coverage: CVEReports.

Downstream fixes: Five errata shipped. Checked 2026-09-06.

Sources: RHSA-2026:17546 · RHSA-2026:24359 · RHSA-2026:24484 · RHSA-2026:26519 · RHSA-2026:26538.

Downstream fixes; the vendor CVE acknowledgement field does not name a reporter.

CVE-2026-41263
GHSA-6x2q-h3cr-8j2h
🟡 Moderate
2026‑04‑24

The earlier BasicAuth timing fix resolved its fallback secret to an empty string, avoiding the intended bcrypt work. Repeated authentication timing measurements could distinguish registered usernames from nonexistent ones on a reachable protected route.

Versions, credits, and sources

GHSA-6x2q-h3cr-8j2h

Maintainer advisory · Published 2026-04-24 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 4.0 6.3.

GitHub global record · Indexed 2026-04-24.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.3; CVSS 3.1 3.7.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-208.

Maintainer package records

Package Affected Fixed
Traefik <= v2.11.42, <= v3.6.13, <= v3.7.0-rc.1 v2.11.43, v3.6.14, v3.7.0-rc.2

GitHub global package records

Package Affected Fixed
github.com/traefik/traefik/v3 >= 3.7.0-ea.1, < 3.7.0-rc.2 3.7.0-rc.2
github.com/traefik/traefik/v3 >= 3.0.0-beta1, < 3.6.14 3.6.14
github.com/traefik/traefik/v2 < 2.11.43 2.11.43
github.com/traefik/traefik <= 1.7.34 Not specified

CVE-2026-41263

CVE CNA source

CVE CNA: CVSS 4.0 6.3. CNA version record — traefik: affected: < 2.11.43; affected: >= 3.0.0-beta1, < 3.6.14; affected: >= 3.7.0-ea.1, < 3.7.0-rc.2.

NVD record

Incomplete fix: CVE-2026-32595. The fallback secret remained empty, so the intended bcrypt timing mitigation was ineffective.

GHSA-qp9x-wp8f-qgjj 🟡 Moderate
2026‑05‑18

Delegation glob matching used platform-dependent case normalization. On Windows, an attacker controlling a delegated role could exploit a case-colliding pattern visited first to serve targets intended for another delegation; POSIX matching was unaffected.

Versions, credits, and sources

GHSA-qp9x-wp8f-qgjj

Maintainer advisory · Published 2026-05-18 · Checked 2026-09-06

Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 4.0.

GitHub global record · Indexed 2026-05-28.

Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 4.0.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-178.

Maintainer package records

Package Affected Fixed
tuf <= 6.0.0 7.0.0

GitHub global package records

Package Affected Fixed
tuf <= 6.0.0 7.0.0

V

Merged patch 2026-03-29
committed

Correct the vim_fgets() size bound in patch 9.2.0271; follow-up in 9.2.0272

Credit and sources

Merged patch: Authored by kodareef5. Checked 2026-09-06.

W

CVE-2026-53445
GHSA-7w2h-g83c-jqrp
🟠 High
2026‑05‑30

The copyBoard method did not verify board membership or administrator rights. A logged-in user could copy a private board and its cards and checklists, then make the resulting copy public through supplied properties.

Versions, credits, and sources

GHSA-7w2h-g83c-jqrp

Maintainer advisory · Published 2026-05-30 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter).

Maintainer weaknesses: CWE-862.

Maintainer package records

Package Affected Fixed
wekan/wekan <= 9.08 9.09

CVE-2026-53445

CVE CNA source

CVE CNA: CVSS 4.0 7.1. CNA version record — wekan: affected: < 9.32.

NVD record

CVE-2026-77308
GHSA-ggg4-v8vp-jxqh
🔴 Critical
2026‑07‑10

Witness automatically loaded repository-local configuration before commands. An untrusted pull request could redirect attestation uploads and disable sensitive-variable filtering, exposing environment secrets available to a CI job that ran witness on that checkout.

GHSA-88v8-jcjq-95w5 🟠 High
2026‑07‑10

Certificate-loading code assigned intermediate certificates to the root pool instead of the intermediate pool. Verification failed for affected intermediate-CA hierarchies; deployments using certificates signed directly by a configured root were unaffected.

Versions, credits, and sources

GHSA-ggg4-v8vp-jxqh

Maintainer advisory · Published 2026-07-10 · Checked 2026-09-06

Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score.

CVSS: no structured score available from the checked sources.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter), jkjell (remediation developer).

Maintainer weaknesses: CWE-15.

Maintainer package records

Package Affected Fixed
github.com/in-toto/witness <= v0.10.2 v0.11.0

CVE-2026-77308

Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check.

GHSA-88v8-jcjq-95w5

Maintainer advisory · Published 2026-07-10 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: no structured CVSS score.

CVSS: no structured score available from the checked sources.

Not found in GitHub’s global advisory database at the 2026-09-06 lookup.

Contributors: kodareef5 (reporter), jkjell (remediation developer).

Maintainer weaknesses: CWE-296.

Maintainer package records

Package Affected Fixed
github.com/in-toto/witness <= v0.10.2 v0.11.0

Z

CVE-2026-55672
GHSA-xqxv-4jc2-x56x
🟠 High
2026‑06‑17

Authorization-code exchange and token refresh did not bind the grant to its original client. An attacker who obtained a code or refresh token through a separate flaw could redeem it under another client, including across tenants.

Versions, credits, and sources

GHSA-xqxv-4jc2-x56x

Maintainer advisory · Published 2026-06-17 · Checked 2026-09-06

Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.4.

GitHub global record · Indexed 2026-06-18.

Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.4.

Contributors: kodareef5 (reporter), grvijayan (remediation developer), IAM-marco (remediation reviewer), livio-a (other), cipher-creator (reporter), N008x (reporter).

Maintainer weaknesses: CWE-287, CWE-863.

Maintainer package records

Package Affected Fixed
ZITADEL 4.0.0 - 4.15.1 4.15.2
ZITADEL <=3.4.11 3.4.12

GitHub global package records

Package Affected Fixed
github.com/zitadel/zitadel < 1.80.0-v2.20.0.20260616131956-0973b074b488 1.80.0-v2.20.0.20260616131956-0973b074b488

CVE-2026-55672

CVE CNA source

CVE CNA: CVSS 3.1 7.4. CNA version record — zitadel: affected: >= 4.0.0-rc.1, < 4.15.2; affected: < 3.4.12.

NVD record

Record notes

Advisory counts cover published GitHub advisories with structured credit. Vendor/CVE-only findings, prose acknowledgements, and patches are separate records.

Repository publication dates and maintainer severity labels are used throughout. CVSS versions, source-specific ratings, package fixes, and contributor roles appear under each project. Undated acknowledgements follow dated work; verification dates are not publication dates.

47 advisories were found in GitHub’s global database; 23 were not found there and are linked to their repository publications. These are lookup results, not a claim that repository advisories are private.

Distributions and verification notes

Advisory-only distributions. A record may name multiple weaknesses; these tables are independent.

Maintainer severity

Severity Advisories
🔴 Critical 9
🟠 High 32
🟡 Moderate 24
🔵 Low 5

Language / ecosystem

Editorial grouping by the affected implementation; not inferred from the logo.

Language / ecosystem Advisories
Go 35
JavaScript 11
Python 9
Rust 7
PHP 5
C++ 2
C 1

Published weaknesses

Weakness Advisories
CWE-918 — Server-Side Request Forgery (SSRF) 9
CWE-863 — Incorrect Authorization 7
CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
CWE-862 — Missing Authorization 5
CWE-20 — Improper Input Validation 3
CWE-287 — Improper Authentication 3
CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
CWE-178 — Improper Handling of Case Sensitivity 2
CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 2
CWE-208 — Observable Timing Discrepancy 2
CWE-296 — Improper Following of a Certificate's Chain of Trust 2
CWE-347 — Improper Verification of Cryptographic Signature 2
CWE-1188 — Initialization of a Resource with an Insecure Default 1
CWE-122 — Heap-based Buffer Overflow 1
CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine 1
CWE-15 — External Control of System or Configuration Setting 1
CWE-183 — Permissive List of Allowed Inputs 1
CWE-184 — Incomplete List of Disallowed Inputs 1
CWE-190 — Integer Overflow or Wraparound 1
CWE-201 — Insertion of Sensitive Information Into Sent Data 1
CWE-248 — Uncaught Exception 1
CWE-269 — Improper Privilege Management 1
CWE-285 — Improper Authorization 1
CWE-306 — Missing Authentication for Critical Function 1
CWE-312 — Cleartext Storage of Sensitive Information 1
CWE-345 — Insufficient Verification of Data Authenticity 1
CWE-400 — Uncontrolled Resource Consumption 1
CWE-426 — Untrusted Search Path 1
CWE-470 — Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') 1
CWE-476 — NULL Pointer Dereference 1
CWE-502 — Deserialization of Untrusted Data 1
CWE-59 — Improper Link Resolution Before File Access ('Link Following') 1
CWE-601 — URL Redirection to Untrusted Site ('Open Redirect') 1
CWE-613 — Insufficient Session Expiration 1
CWE-670 — Always-Incorrect Control Flow Implementation 1
CWE-73 — External Control of File Name or Path 1
CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 1
CWE-754 — Improper Check for Unusual or Exceptional Conditions 1
CWE-770 — Allocation of Resources Without Limits or Throttling 1
CWE-776 — Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') 1
CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1
CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Not specified 5

Verification limits

The published advisories supply CVE-2026-35511, CVE-2026-9316, CVE-2026-77308, CVE-2026-73549, CVE-2026-55701, but their public CVE JSON was unavailable at the recorded checks. Their IDs are retained with source-specific notes.

Lyrie Research: Page could not be retrieved during the September 6 review; retained from the earlier record.

See record review for the factual corrections and source policy.

Advisories · Source snapshots · Upstream work · Upstream provenance · Standalone sources · Editorial data · Project marks

GitHub · kodareef5@gmail.com

Popular repositories Loading

  1. sha256-probe sha256-probe Public

    SHA-256 schedule compliance cryptanalysis toolkit — probing the sr=59/sr=60 boundary

    Python 4

  2. spacewasm spacewasm Public

    Forked from nasa/spacewasm

    A flight-compliant WebAssembly interpreter.

    Rust 1

  3. plan-guard plan-guard Public

    Automatic plan file backup and recovery for Claude Code. Never lose a plan to context compaction again.

    Shell 2

  4. dn-institute dn-institute Public archive

    Forked from 1712n/dn-institute

    Distributed Networks Institute

    Python

  5. tinygrad tinygrad Public archive

    Forked from tinygrad/tinygrad

    You like pytorch? You like micrograd? You love tinygrad! ❤️

    Python

  6. product-kit-template product-kit-template Public archive

    Forked from tysoncung/ai-security-digest

    HTML