Security research and contributions to open-source software.
Projects / Work / Record notes
AVideo · bitbang-cli · bitbang-server · DOMPurify · gitoxide · GNOME GLib · go-git · gosaml2 · jsrsasign · libevent · libheif · libjpeg-turbo · libzip · lighttpd · phpseclib · pypdf · RustFS · simple-git · StableLib
73 projects · 70 published advisories · 12 merged patches
Alphabetical by project; newest work first within each.
A B C D E F G H J K L N O P R S T V W Z
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-73081 GHSA-3pfv-m69p-5fv5 |
🟠 High 2026‑07‑17 |
||||||
|
A flow Code step’s name reached a shell-invoked bun build command without sufficient validation. An authenticated user able to create a flow could execute commands as the worker user before sandboxing began. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-17 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 4.0 8.7. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: p80n-sec (reporter), kodareef5 (reporter), Aviral2642 (reporter). Maintainer package records
CVE CNA: CVSS 4.0 8.7. CNA version record — activepieces: affected: < 0.80.0. Coverage: HackerNoon · Aviral Srivastava. | |||||||
| ↑ | |
|---|---|
| Merged patch | 2026-04-16 committed |
|
Integer overflow guards in four core escaping functions | |
Credit and sourcesMerged patch: Submitted by: Koda Reef. Checked 2026-09-06. | |
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41321 GHSA-88gm-j2wx-58h6 |
🔵 Low 2026‑04‑20 |
||||||||||||
|
The Cloudflare image-binding transform checked only the initial remote-image URL and followed redirects. An open redirect on an allowed domain could bypass image-domain restrictions and trigger blind requests to destinations outside that allowlist. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-20 · Checked 2026-09-06 Maintainer severity: 🔵 Low. Maintainer: CVSS 3.1 2.2. GitHub global record · Indexed 2026-04-23. Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.0; CVSS 3.1 2.2. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 2.2. CNA version record — @astrojs/cloudflare: affected: < 13.1.10. Incomplete fix: GHSA-qpr4-c339-7vq8. Redirect controls added to other image paths were absent from the Cloudflare image-binding transform. | |||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-41577 GHSA-4v4x-x5pr-8gp2 |
🟡 Moderate 2026‑05‑12 |
||||||
|
SAML assertion processing omitted time and audience conditions. An attacker holding a valid signed assertion could replay it after its signed expiry or use an assertion issued for a different service provider. | |||||||
| Vendor acknowledgement | |||||||
|
SAML NameID truncation in CVE-2026-40165 | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-05-12 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter), Android-Login-Analysis (reporter), AyushParkara (reporter). Maintainer weaknesses: CWE-345. Maintainer package records
CVE CNA: CVSS 4.0 6.9. CNA version record — authentik: affected: < 2025.12.5; affected: < 2026.2.3. Vendor acknowledgement: Named on the vendor CVE page. Checked 2026-09-06. | |||||||
| ↑ | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-35511 GHSA-29rf-f4vv-pvq6 |
🔴 Critical 2026‑08‑13 |
||||||||||||||||||||||||
|
OAuth login linked accounts by email without requiring the existing account to verify that address. An attacker who registered a victim’s email retained password access when the victim later signed in through an OAuth provider. | |||||||||||||||||||||||||
| GHSA-x3f4-v83f-7wp2 | 🟠 High 2026‑04‑03 |
||||||||||||||||||||||||
|
Several authentication endpoints attached tokens to caller-supplied redirect URLs without checking AllowedOrigins. An attacker could capture reset, magic-link, or authentication tokens after the victim followed an emailed link leading through the affected flow. | |||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-13 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-08-14. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.7; CVSS 3.x 0.0. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-287. Maintainer package records
GitHub global package records
Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check. Maintainer advisory · Published 2026-04-03 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-06. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.6; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-601. Maintainer package records
GitHub global package records
| |||||||||||||||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-33766 GHSA-f359-r3pv-2phf |
🟡 Moderate 2026‑03‑24 |
||||||||||||
|
Image-download endpoints validated the starting URL but followed HTTP redirects without checking their destinations. A user with upload and edit permissions could redirect the server to internal services or reachable cloud metadata endpoints. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-03-24 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-03-26. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 5.3; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 5.3. CNA version record — AVideo: affected: <= 26.0. | |||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-35043 GHSA-fgv4-6jr3-jgfw |
🔴 Critical 2026‑04‑02 |
||||||||||||
|
Cloud deployment script generation inserted system_packages from bentofile.yaml into a shell command without quoting. An attacker-controlled package entry could execute commands during the BentoCloud build; an earlier local-path quoting fix missed this cloud-specific path. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-02 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-03. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.8. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-78. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.8. CNA version record — BentoML: affected: < 1.4.38. Incomplete fix: commit ce53491. The earlier quoting fix did not cover the cloud deployment setup script. | |||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40077 GHSA-5f5r-95pg-xrpm |
🔵 Low 2026‑04‑09 |
||||||||||||
|
Several hub endpoints checked authentication but not membership of the requested system. Cross-system container access required both a valid 15-character system ID and 12-character container ID; other affected endpoints could disclose system information or trigger SMART refreshes. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-09 · Checked 2026-09-06 Maintainer severity: 🔵 Low. Maintainer: CVSS 3.1 3.5. GitHub global record · Indexed 2026-04-10. Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.0; CVSS 3.1 3.5. Contributors: marduc812 (reporter), kodareef5 (reporter), lakshayyverma (reporter). Maintainer weaknesses: CWE-184. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 3.5. CNA version record — beszel: affected: < 0.18.7. | |||||||||||||
| ↑ | |
|---|---|
| Merged patch | 2026-08-16 merged |
|
Publish a running tmux session as a shareable URL | |
| Merged patch | 2026-08-01 merged |
|
Reachable dnsmessage panic in mDNS response parsing (GO-2026-5942); golang.org/x/net bumped to v0.57.0 | |
Credit and sourcesMerged patch: PR authored by kodareef5 and merged. Checked 2026-09-06. Ordinary open-source contribution. Merged patch: PR merged. Checked 2026-09-06. | |
| ↑ | |
|---|---|
| Merged patch | 2026-08-15 merged |
|
Add bitbang-metrics-dump and a build/test CI workflow | |
Credit and sourcesMerged patch: PR authored by kodareef5 and merged. Checked 2026-09-06. Ordinary open-source contribution. | |
| ↑ | |
|---|---|
| Merged patch | 2026-03-22 merged |
|
Overflow checks in | |
| ↑ | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41520 GHSA-gj49-89wh-h4gj |
🟠 High 2026‑04‑22 |
||||||||||||||||||||||||
|
Debug archives from WireGuard-enabled Cilium nodes included the node’s WireGuard private key. Anyone receiving an affected bugtool archive or sysdump obtained that key; remediation required rotating keys already shared in diagnostic bundles. | |||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-22 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.9. GitHub global record · Indexed 2026-04-25. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.9. Contributors: tklauser (remediation developer), kodareef5 (reporter). Maintainer weaknesses: CWE-200, CWE-312. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.9. CNA version record — cilium: affected: < 1.17.15; affected: >= 1.18.0, < 1.18.9; affected: >= 1.19.0, < 1.19.3. | |||||||||||||||||||||||||
| ↑ | |
|---|---|
| Upstream acknowledgement | 2026-05-07 committed |
|
Recovery target validation | |
| Upstream acknowledgement | 2026-04-29 committed |
|
Escaping in PostgreSQL configuration values | |
Credit and sourcesUpstream acknowledgement: Suggested-by: Koda Reef. Checked 2026-09-06. Upstream acknowledgement: Reported-by: Koda Reef. Checked 2026-09-06. | |
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-56671 GHSA-pj59-g5vv-74q4 |
🟠 High 2026‑07‑15 |
||||||
|
The unauthenticated model-preview route accepted paths outside its model directory. Because responses were decoded and re-encoded as images, disclosure was limited to image-decodable files, with a separate oracle revealing whether other files existed. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-15 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.5. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kartikganesh (finder), yd1ng (finder), sfwani (finder), icysun (finder), kodareef5 (finder), Tulgaaaaaaaa (finder). Maintainer weaknesses: CWE-22. Maintainer package records
CVE CNA: CVSS 3.1 7.5. CNA version record — ComfyUI: affected: < 0.28.0. | |||||||
| ↑ | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40261 GHSA-gqw4-4w2p-838q |
🟠 High 2026‑04‑14 |
||||||||||||||||||
|
Perforce package references and connection parameters entered shell commands without escaping. A repository supplying malicious Perforce source metadata could execute commands during source-preferred Composer installs, even when the Perforce client was not installed. | |||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-14 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.8. GitHub global record · Indexed 2026-04-14. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.8. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-20, CWE-78. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 8.8. CNA version record — composer: affected: >= 2.3.0, < 2.9.6; affected: >= 1.0.0, < 2.2.27. | |||||||||||||||||||
| ↑ | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41246 GHSA-x4mj-7f9g-29h4 |
🟠 High 2026‑04‑20 |
||||||||||||||||||
|
Cookie rewrite values entered generated Envoy Lua code without escaping. A user permitted to create or modify HTTPProxy resources could execute Lua in shared Envoy, read its xDS credentials, and potentially access other tenants’ TLS keys. | |||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-20 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.1. GitHub global record · Indexed 2026-04-24. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.1. Contributors: b0b0haha (reporter), kodareef5 (reporter). Maintainer weaknesses: CWE-94. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 8.1. CNA version record — contour: affected: >= 1.33.0, < 1.33.4; affected: >= 1.32.0, < 1.32.5; affected: >= 1.19.0, < 1.31.6. Coverage: ZeroPath. | |||||||||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-34168 GHSA-mh8x-fppq-cp77 |
🟠 High 2026‑07‑02 |
||||||
|
Persistent-volume names entered shell commands without escaping during resource deletion. An authenticated API token holder able to configure storage could arrange command execution as root on managed servers when the affected resource was deleted. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-02 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.8. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-78. Maintainer package records
CVE CNA: CVSS 3.1 8.8. CNA version record — coolify: affected: < 4.0.0-beta.471. Related work: CVE-2025-66213. The same shell-injection pattern occurred in other resource models; this is related work, not a demonstrated bypass of the identical patched path. | |||||||
| ↑ | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-39395 GHSA-w6c6-c85g-mmv6 |
🟡 Moderate 2026‑04‑06 |
|||||||||||||||
|
Attestation verification mishandled predicate-type and payload-parsing failures across bundle formats. Without check-claims enabled, a valid signature over an unparsable payload or mismatched predicate type could still produce a successful verification result. | ||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-06 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 4.3. GitHub global record · Indexed 2026-04-08. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 4.3. Contributors: kodareef5 (reporter). Global weaknesses: CWE-754. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 4.3. CNA version record — cosign: affected: >= 3.0.0, < 3.0.6; affected: < 2.6.3. | ||||||||||||||||
| ↑ | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-34976 GHSA-p5rh-vmhp-gvcw |
🔴 Critical 2026‑04‑02 |
||||||||||||||||||
|
The restoreTenant mutation lacked its authorization middleware entry. Unauthenticated callers reaching the admin GraphQL endpoint could overwrite a namespace from a supplied backup, probe local filesystem paths, or trigger requests through a controlled vault address. | |||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-02 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-02. Global severity: 🔴 Critical. GitHub global: CVSS 4.0 0.0; CVSS 3.1 10.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-862. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 10. CNA version record — dgraph: affected: < 25.3.1. Coverage: GBHackers · Cybersecurity News. | |||||||||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41240 GHSA-h7mw-gpvr-xq4m |
🟡 Moderate 2026‑04‑20 |
||||||||||||
|
Function-based ADD_TAGS handling skipped FORBID_TAGS when the predicate returned true. Configurations combining those options could retain explicitly forbidden elements and their permitted attributes; the corresponding attribute-denylist path already had an earlier fix. Merged patch · 2026-04-11 (merged) — Fix for CVE-2026-41240 | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-20 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-22. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.0; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-183. Global weaknesses: CWE-79, CWE-183. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 6. CNA version record — DOMPurify: affected: < 3.4.0. Incomplete fix: commit c361baa. The earlier FORBID_ATTR precedence fix did not cover the equivalent FORBID_TAGS case. Merged patch: PR merged. Checked 2026-09-06. Sources: CVE-2026-41240. | |||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-73549 GHSA-jp5f-qr64-c9vw |
🟡 Moderate 2026‑08‑26 |
||||||
|
Scoped IPv6 addresses could crash copyInternetAddressAndPort in ORIGINAL_DST or transparent-proxy paths. Exploitation depends on original-destination socket handling; the advisory reports source analysis, not a live reproduced exploit, and extends an earlier IPv6 fix. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-26 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 5.3. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter), antoniovleonti (remediation developer), phlax (coordinator), nezdolik (coordinator). Maintainer weaknesses: CWE-754. Maintainer package records
Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check. Incomplete fix: CVE-2026-26310. The scoped-IPv6 fix in getAddressWithPort missed copyInternetAddressAndPort. | |||||||
| ↑ | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-34984 GHSA-r2pg-r6h7-crf3 |
🟠 High 2026‑04‑11 |
|||||||||||||||
|
The template engine exposed getHostByName inside the controller process. A user able to author templated ExternalSecret resources could encode accessible secrets into DNS lookups; exploitation required outbound DNS from the controller, not direct egress from the attacker’s workload. | ||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-11 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-13. Global severity: 🟠 High. GitHub global: CVSS 4.0 7.1; CVSS 3.1 6.5. Contributors: kodareef5 (reporter). Global weaknesses: CWE-200. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 7.1. CNA version record — external-secrets: affected: < 2.3.0. | ||||||||||||||||
| ↑ | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-35604 GHSA-v9w4-gm2x-6rvf |
🟠 High 2026‑04‑04 |
||||||||||||||||||||||||||||||||||||||||||||||||
|
Public share access did not recheck the owner’s Share and Download permissions. Existing links remained downloadable after an administrator revoked those permissions, even though the same account could no longer create new shares. Merged patch · 2026-04-04 (merged) — Share owner permissions checked on public share access | |||||||||||||||||||||||||||||||||||||||||||||||||
| CVE-2026-35607 GHSA-7526-j432-6ppp |
🟡 Moderate 2026‑04‑04 |
||||||||||||||||||||||||||||||||||||||||||||||||
|
Proxy-authenticated accounts inherited default Execute permissions and configured commands, unlike ordinary signup accounts. Exposure required proxy authentication with command execution enabled and permissive administrator-configured defaults; the earlier signup fix did not cover auto-provisioning. Merged patch · 2026-04-04 (merged) — Default permissions restricted for proxy-auth auto-provisioned users | |||||||||||||||||||||||||||||||||||||||||||||||||
| CVE-2026-35606 GHSA-67cg-cpj7-qgc9 |
🟡 Moderate 2026‑04‑04 |
||||||||||||||||||||||||||||||||||||||||||||||||
|
The resource endpoint returned text content and raw encoded bytes without checking Download permission. An authenticated user with downloads disabled could still read files within their authorized scope; directory and path authorization remained in effect. Merged patch · 2026-04-04 (merged) — Download permission checked in the resource handler | |||||||||||||||||||||||||||||||||||||||||||||||||
| CVE-2026-35605 GHSA-5q48-q4fm-g3m6 |
🟡 Moderate 2026‑04‑04 |
||||||||||||||||||||||||||||||||||||||||||||||||
|
Access-rule matching used a string prefix without enforcing a directory boundary. An allow rule for one directory could also admit a sibling whose name shared that prefix; deny rules could over-match for the same reason. Merged patch · 2026-04-04 (merged) — Directory boundaries enforced in access-rule path matching | |||||||||||||||||||||||||||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-04 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-08. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.2; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-863. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 8.2. CNA version record — filebrowser: affected: < 2.63.1. Merged patch: PR merged. Checked 2026-09-06. Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-08. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.1. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-269. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 8.1. CNA version record — filebrowser: affected: < 2.63.1. Incomplete fix: GHSA-x8jc-jvqm-pm3f. Signup permissions were restricted, but proxy-auth auto-provisioning kept the old defaults. Merged patch: PR merged. Checked 2026-09-06. Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-08. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 5.3; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-862. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 5.3. CNA version record — filebrowser: affected: < 2.63.1. Merged patch: PR merged. Checked 2026-09-06. Maintainer advisory · Published 2026-04-04 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-08. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.3; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-22. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 6.3. CNA version record — filebrowser: affected: < 2.63.1. Merged patch: PR merged. Checked 2026-09-06. | |||||||||||||||||||||||||||||||||||||||||||||||||
| ↑ | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41050 GHSA-765j-qfrp-hm3j |
🔴 Critical 2026‑04‑30 |
||||||||||||||||||||||||||||||||||||
|
Helm lookup and valuesFrom reads bypassed ServiceAccount impersonation and retained fleet-agent privileges. A tenant able to push to a monitored Git repository could read other namespaces’ secrets on targeted downstream clusters; single-tenant deployments were unaffected. | |||||||||||||||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-30 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: CVSS 3.1 9.9. GitHub global record · Indexed 2026-05-07. Global severity: 🔴 Critical. GitHub global: CVSS 4.0 0.0; CVSS 3.1 9.9. Contributors: kodareef5 (reporter). Global weaknesses: CWE-863. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 9.9. CNA version record — Rancher: affected: 0.15.0 < 0.15.1; affected: 0.14.0 < 0.14.5; affected: 0.13.0 < 0.13.10; affected: 0.12.0 < 0.12.14; affected: 0.11.0 < 0.11.13. Coverage: GBHackers · CyberPress · Lyrie Research. Lyrie Research: Page could not be retrieved during the September 6 review; retained from the earlier record. | |||||||||||||||||||||||||||||||||||||
| ↑ | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-9cvr-5wv9-2gxr | 🟠 High 2026‑08‑31 |
|||||||||
|
Cheerio, Playwright, and Puppeteer document loaders fetched URLs outside Flowise’s shared HTTP-security checks. A user able to configure these loaders could bypass the denylist and request internal destinations; the earlier HTTP-node fix did not cover them. | ||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-31 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 4.0 7.6. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
Incomplete fix: FlowiseAI/Flowise#5886. The HTTP-node SSRF fix did not cover document loaders. | ||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-34443 GHSA-c9v3-4c59-x5q2 |
🟠 High 2026‑03‑30 |
||||||
|
The SSRF address check returned early for ordinary IP addresses, leaving configured CIDR blocks unenforced. An inbound email containing controlled attachment URLs could cause the server to request private-network destinations that the policy intended to block. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-03-30 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
CVE CNA: CVSS 4.0 6.9. CNA version record — freescout: affected: < 1.8.211. | |||||||
| ↑ | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-34172 GHSA-frv4-x25r-588m |
🟠 High 2026‑03‑26 |
||||||||||||||||||
|
ChatWorkflow.chat treated plain-string input as a Jinja2 template in an unsandboxed environment. Applications passing untrusted input directly to that method could expose command execution; values supplied through with_inputs did not take the vulnerable template-compilation path. | |||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-03-26 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-03-27. Global severity: 🟠 High. GitHub global: CVSS 4.0 7.7; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-1336. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 7.7. CNA version record — giskard-oss: affected: < 0.3.4; affected: >= 1.0.1a1, < 1.0.2b1. | |||||||||||||||||||
| ↑ | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-82254 GHSA-x494-mj8g-cj27 |
🟠 High 2026‑04‑25 |
||||||||||||||||||||||||||||||
|
Unchecked delta indexing and uncapped allocations allowed crafted Git pack data to crash consuming processes. A malicious remote could trigger a truncated-delta panic or excessive allocation during clone and fetch operations. | |||||||||||||||||||||||||||||||
| CVE-2026-82253 GHSA-p3hw-mv63-rf9w |
🟠 High 2026‑04‑25 |
||||||||||||||||||||||||||||||
|
Incomplete submodule-name validation allowed paths to escape .git/modules, while inherited trust skipped ownership checks. Processing attacker-controlled submodule metadata could access unintended Git configuration and disclose credentials; package fix versions differ between published sources. | |||||||||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-25 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-05-05. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.7; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-248, CWE-770. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 8.7; CVSS 3.1 7.5. CNA version record — gitoxide: affected: 0 < 0.69.0; unaffected: 0.69.0. Maintainer advisory · Published 2026-04-25 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-05-05. Global severity: 🟠 High. GitHub global: CVSS 4.0 7.5; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-22, CWE-200. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 8.7; CVSS 3.1 7.5. CNA version record — gitoxide: affected: 0 < 0.82.0; unaffected: 0.82.0. CNA version record — gitoxide: affected: 0 < 0.11.1; unaffected: 0.11.1. | |||||||||||||||||||||||||||||||
| ↑ | |
|---|---|
| Upstream acknowledgement | 2026-04-29 committed |
|
D-Bus message length integer arithmetic | |
Credit and sourcesUpstream acknowledgement: Based on a report by Koda Reef. Checked 2026-09-06. | |
| ↑ | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-71556 GHSA-hc8v-wwc9-vgxm |
🟠 High 2026‑07‑30 |
||||||||||||||||||||||||||||||||||||
|
Worktree writes checked path strings but followed existing symlinks. An attacker able to plant a symlink and trigger a write could escape the worktree or modify Git metadata, including configuration beneath .git. | |||||||||||||||||||||||||||||||||||||
| GHSA-w5pp-99ch-qj29 | 🟡 Moderate 2026‑05‑18 |
||||||||||||||||||||||||||||||||||||
|
Crafted pack, index, or loose-object data could cause panics or excessive resource use. Applications cloning, fetching, or opening untrusted repositories were exposed through a malicious remote or attacker-controlled files under .git/objects. | |||||||||||||||||||||||||||||||||||||
| Report acknowledgement | |||||||||||||||||||||||||||||||||||||
|
CVE-2026-45571 report | |||||||||||||||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-30 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.1. GitHub global record · Indexed 2026-08-07. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.1. Contributors: kodareef5 (reporter), HughLewis20 (reporter). Maintainer weaknesses: CWE-59. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.1. CNA version record — go-git: affected: < 5.19.2; affected: >= 6.0.0-alpha.1, < 6.0.0-alpha.5. Maintainer advisory · Published 2026-05-18 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.5. GitHub global record · Indexed 2026-05-29. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 6.5. Contributors: hiddeco (remediation developer), N0zoM1z0 (reporter), AyushParkara (reporter), kodareef5 (reporter). Maintainer weaknesses: CWE-400. Maintainer package records
GitHub global package records
Report acknowledgement: Thanks to @kodareef5, @AyushParkara and @N0zoM1z0 for reporting this to the go-git project in three separate reports. Checked 2026-09-06. Named in the advisory body, not its structured credit list. | |||||||||||||||||||||||||||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| GHSA-6xq9-h39h-jc22 | 🔵 Low 2026‑07‑10 |
||||||
|
Policy verification appended the intermediate pool to itself instead of loading certificates from the trust bundle. Attestations requiring an intermediate CA failed verification; the failure was closed and did not accept unverified attestations. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-10 · Checked 2026-09-06 Maintainer severity: 🔵 Low. Maintainer: no structured CVSS score. CVSS: no structured score available from the checked sources. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter), jkjell (remediation developer). Maintainer weaknesses: CWE-296. Maintainer package records
| |||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| GHSA-vv4x-5gvr-chh8 | 🟡 Moderate 2026‑08‑19 |
||||||
|
The earlier LogoutRequest signature fix did not cover LogoutResponse validation. Applications using the affected POST-response validator could accept an unsigned SAML logout response; independent reports were combined in the published advisory. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-19 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 5.3. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter), tonghuaroot (reporter). Maintainer weaknesses: CWE-347. Maintainer package records
Incomplete fix: GHSA-pcgw-qcv5-h8ch. The LogoutRequest signature fix was not applied to LogoutResponse validation. | |||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-qmwh-9m9c-h36m | 🟠 High 2026‑04‑06 |
||||||||||||
|
The ExifTool metadata filter was case-sensitive and omitted hard-link and symbolic-link tags. Callers of the metadata-write endpoint, unauthenticated by default, could write files or links outside intended paths, within the service’s filesystem permissions. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-06 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-07. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.8; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-73, CWE-178. Maintainer package records
GitHub global package records
Incomplete fix: commit 043b158. The ExifTool blocklist remained case-sensitive and omitted hard-link and symlink tags. | |||||||||||||
| ↑ | |
|---|---|
| Release acknowledgement | 2026-05-07 released |
|
Host-header validation in v0.42.0 | |
Credit and sourcesRelease acknowledgement: thanks to Koda Reef for reporting the issue. Checked 2026-09-06. | |
| ↑ | |
|---|---|
| Release acknowledgement | 2026-04-13 released |
|
DSA universal signature forgery from a missing FIPS 186-4 §4.7 boundary check, fixed in 11.1.2 | |
| Release acknowledgement | 2026-04-13 released |
|
ASN.1 parser infinite loop in | |
Credit and sourcesRelease acknowledgement: reported by Koda Reef, Nicholas Carlini and @Kr0emer. Checked 2026-09-06. Sources: Release archive. Release acknowledgement: reported by Koda Reef. Checked 2026-09-06. Sources: Release archive. | |
| ↑ | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41326 GHSA-q49m-57vm-c8cc |
🔴 Critical 2026‑04‑22 |
|||||||||||||||
|
CopyFile policy checked the destination path but not the symlink target supplied in request data. An untrusted host could redirect writes outside the shared directory and overwrite files inside the guest, including in confidential-container deployments. | ||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-22 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-05-04. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.2; CVSS 3.1 8.2. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: fitzthum (reporter), calonso-nv (finder), fikriwahab (finder), burgerdev (remediation developer), danmihai1 (remediation reviewer), jojimt (remediation reviewer), fidencio (remediation reviewer), kodareef5 (finder). Global weaknesses: CWE-61. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 8.2. CNA version record — kata-containers: affected: >= 3.4.0, < 3.29.0. | ||||||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-65956 GHSA-wjrh-4j52-c664 |
🟡 Moderate 2026‑08‑04 |
||||||
|
SSO configuration and connectivity-test endpoints were exposed outside the intended management boundary. Depending on authentication settings and deployment configuration, unauthenticated or low-privilege callers could alter SSO settings, potentially take over accounts, or trigger server-side requests. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-04 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-306. Maintainer package records
CVE CNA: CVSS 4.0 10. CNA version record — KubePi: affected: < 2.0.0. | |||||||
| ↑ | |
|---|---|
| Release acknowledgement | |
|
HTTP header parsing restricted against request smuggling | |
Credit and sourcesRelease acknowledgement: Named in release notes. Checked 2026-09-06. Sources: GHSA-q39v-w2g7-gr8j · CVE-2026-63382. Named in the changelog; not counted as a structured advisory credit. | |
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| GHSA-9h96-c44j-jpq9 | 🟠 High 2026‑05‑19 |
||||||
|
A 32-bit stride calculation could wrap for large image widths, allocating an undersized plane. Processing a crafted HEIF or AVIF image could then overflow the heap, crashing or potentially compromising the consuming application. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-05-19 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. CVSS: no structured score available from the checked sources. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-122, CWE-190. Maintainer package records
| |||||||
| ↑ | |
|---|---|
| Report and fixes | |
|
Signed-overflow bounds checks across six JNI paths | |
Credit and sourcesReport and fixes: Issue fixed across three commits linked with Fixes #877. Checked 2026-09-06. | |
| ↑ | |
|---|---|
| Acknowledgement | |
|
Listed in THANKS | |
Credit and sourcesAcknowledgement: kodareef5. Checked 2026-09-06. | |
| ↑ | |
|---|---|
| Upstream acknowledgement | 2026-05-04 committed |
|
| |
Credit and sourcesUpstream acknowledgement: (thx kodareef5). Checked 2026-09-06. | |
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-9316 GHSA-2j37-g5f6-h55p |
🟠 High 2026‑08‑26 |
||||||
|
The proxy accepted a base-url-override header while its default network denylist was empty. Callers with a valid secret key or environment:proxy scope could direct authenticated proxy requests to private-network and metadata addresses. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-26 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. CVSS: no structured score available from the checked sources. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: geo-chen (finder), KatrielMoses (finder), kodareef5 (finder), sajdakabir (finder), endscene665 (finder). Maintainer weaknesses: CWE-918, CWE-1188. Maintainer package records
Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check. | |||||||
| ↑ | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Release acknowledgement | 2026-06-29 released |
||||||||||||||||||
|
Non-CVE fixes acknowledged in v2.14.3 and v2.12.12 | |||||||||||||||||||
| CVE-2026-58254 GHSA-p3j5-5hrq-p75h |
🟡 Moderate 2026‑06‑29 |
||||||||||||||||||
|
Trace-destination permissions were not consistently checked for traffic arriving over leafnode connections. A leafnode operator could direct trace events to disallowed subjects, exposing routing and account metadata, and suppress normal message delivery. | |||||||||||||||||||
| CVE-2026-58214 GHSA-4g68-3pwx-5vfj |
🟡 Moderate 2026‑06‑29 |
||||||||||||||||||
|
An internal-subject restriction omitted the MQTT delivery PUBREL family. Authenticated MQTT clients could bypass subscribe permissions and receive account-local QoS2 protocol metadata; the published impact did not include message payload disclosure. | |||||||||||||||||||
| CVE-2026-58250 GHSA-3g5q-cfh2-cq67 |
🟠 High 2026‑06‑29 |
||||||||||||||||||
|
Repeated pre-authentication leafnode INFO messages could leave handshake state unset and crash the server. Exploitation required access to a leafnode listener with compression enabled; disabling that compression mitigated the affected path. | |||||||||||||||||||
Versions, credits, and sourcesRelease acknowledgement: Koda Reef in contributors. Checked 2026-09-06. Sources: Release archive · v2.12.12. Maintainer advisory · Published 2026-06-29 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-863. Maintainer package records
CVE CNA: CVSS 4.0 5.3. CNA version record — nats-server: affected: < 2.12.8; affected: >= 2.14.0-RC.1, < 2.14.3. Incomplete fix: CVE-2026-33249. Leafnode traffic still bypassed trace-destination permission checks. Maintainer advisory · Published 2026-06-29 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 4.3. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-863. Maintainer package records
CVE CNA: CVSS 3.1 4.3. CNA version record — nats-server: affected: < 2.12.12; affected: >= 2.14.0-RC.1, < 2.14.3. Incomplete fix: CVE-2026-33217. The MQTT internal-subject restriction omitted the Maintainer advisory · Published 2026-06-29 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.6. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-476. Maintainer package records
CVE CNA: CVSS 3.1 7.5. CNA version record — nats-server: affected: < 2.11.17; affected: >= 2.12.0-preview.1, < 2.12.8. Incomplete fix: CVE-2026-29785 · CVE-2026-33218. The pre-auth leafnode crash remained after two earlier fixes. | |||||||||||||||||||
| ↑ | |
|---|---|
| Changelog acknowledgement | |
|
Constant-time | |
Credit and sourcesChangelog acknowledgement: Thanks to kodareef5. Checked 2026-09-06. | |
| ↑ | |
|---|---|
| CVE-2026-77180 Vendor/CVE record |
🟠 High 2026‑09‑02 |
|
An authenticated user able to modify Kubernetes Ingress annotations could inject NGINX configuration. The vendor describes a control-plane issue requiring configuration access, not direct exploitation through data-plane traffic. | |
Versions, credits, and sourcesF5 CNA credits kodareef5 as reporter. CVE CNA: CVSS 4.0 8.7; CVSS 3.1 8.3. CNA version record — NGINX Ingress Controller: affected: 5.0.0 < 5.6.0; affected: 2026-lts-r1 < 2026-lts-r5. Standalone finding; excluded from GitHub advisory statistics. | |
| ↑ | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-4x48-cgf9-q33f | 🟠 High 2026‑04‑13 |
|||||||||||||||
|
Conditions-filter webhooks bypassed the URL checks used by the HTTP Request step. A user with workflow-configuration access could issue server-side POST requests to internal endpoints and read responses through execution details. | ||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-13 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-14. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
GitHub global package records
| ||||||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40574 GHSA-c5c4-8r6x-56w3 |
🟡 Moderate 2026‑04‑14 |
||||||||||||
|
Email-domain validation accepted malformed claims containing multiple at signs, allowing an unintended domain suffix to match the allowlist. Exploitation required an identity provider capable of emitting such malformed claims; providers enforcing email syntax were unaffected. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-14 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.8. GitHub global record · Indexed 2026-04-15. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 6.8. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-20. Global weaknesses: CWE-863. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 6.8. CNA version record — oauth2-proxy: affected: < 7.15.2. | |||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-34759 GHSA-6wc5-rhvj-cx7f |
🔴 Critical 2026‑03‑30 |
||||||
|
Notification phone-number routes omitted service authorization and performed privileged operations. Using a project ID exposed by the status-page API, an unauthenticated caller could purchase Twilio numbers on the deployment’s account or release numbers used for alerts. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-03-30 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-862. Maintainer package records
CVE CNA: CVSS 4.0 9.2. CNA version record — oneuptime: affected: < 10.0.42. | |||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-55701 GHSA-w5cv-pw74-4rxc |
🟡 Moderate 2026‑06‑15 |
||||||||||||
|
The GitHub receiver validated RequiredHeaders configuration but never enforced it on incoming requests. With the shared secret left at its empty default, callers could submit arbitrary webhook payloads and inject false CI/CD trace data. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-06-15 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-06-18. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.9; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-863. Maintainer package records
GitHub global package records
Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check. | |||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-39883 GHSA-hfvc-g4fc-pqhx |
🟠 High 2026‑04‑08 |
||||||||||||
|
Host-ID lookup invoked kenv by name instead of an absolute path. On affected BSD and Solaris paths, a local attacker controlling an earlier PATH directory could run a replacement executable inside the OpenTelemetry-using process. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-08 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-08. Global severity: 🟠 High. GitHub global: CVSS 4.0 7.3; CVSS 3.x 0.0. Contributors: kodareef5 (reporter), dmathieu (remediation developer). Maintainer weaknesses: CWE-426. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 7.3. CNA version record — opentelemetry-go: affected: >= 1.15.0, < 1.43.0. Incomplete fix: GHSA-9h8m-3fm2-qjrq. The earlier absolute-path fix covered ioreg but not kenv. | |||||||||||||
| ↑ | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40194 GHSA-r854-jrxh-36qx |
🔵 Low 2026‑04‑10 |
||||||||||||||||||||||||
|
SSH packet authentication compared HMACs with a variable-time operator instead of hash_equals. The timing difference is a defense-in-depth concern: authentication failure disconnects and rekeys the session, and the advisory does not establish a practical remote exploit. | |||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-10 · Checked 2026-09-06 Maintainer severity: 🔵 Low. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-10. Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.0; CVSS 3.1 3.7. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-208. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 3.7. CNA version record — phpseclib: affected: >= 0.1.1, < 1.0.28; affected: >= 2.0.0, < 2.0.53; affected: >= 3.0.0, < 3.0.51. | |||||||||||||||||||||||||
| ↑ | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-43983 GHSA-w6p7-2fxx-4f44 |
🟠 High 2026‑04‑26 |
||||||||||||||||||||||||
|
Refreshing an OIDC token did not recheck account disabling, authorization revocation, or group restrictions. Holders of an existing refresh token and the required client credentials could continue obtaining tokens after administrators removed access. | |||||||||||||||||||||||||
| GHSA-hp74-gm6m-2qm5 | 🟡 Moderate 2026‑04‑26 |
||||||||||||||||||||||||
|
The reauthentication fallback checked access-token freshness and a session cookie, but not how login occurred. A stolen one-time access token could therefore satisfy step-up requirements and obtain tokens for protected OIDC clients. | |||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-26 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-07-28. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.5; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-285, CWE-613. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 8.5. CNA version record — pocket-id: affected: < 2.6.0. Maintainer advisory · Published 2026-04-26 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-07-28. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.0; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-287. Maintainer package records
GitHub global package records
| |||||||||||||||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41140 GHSA-73h3-mf4w-8647 |
🔵 Low 2026‑04‑18 |
||||||||||||
|
On Python versions lacking tarfile’s data filter, Poetry extracted source distributions without traversal protection. Crafted archive members could escape the extraction directory during dependency resolution; the advisory rates this low because package build backends already execute code. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-18 · Checked 2026-09-06 Maintainer severity: 🔵 Low. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-22. Global severity: 🔵 Low. GitHub global: CVSS 4.0 0.6; CVSS 3.x 0.0. Contributors: kodareef5 (reporter), radoering (remediation reviewer). Maintainer weaknesses: CWE-22. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 0.6. CNA version record — poetry: affected: < 2.3.4. | |||||||||||||
| ↑ | |
|---|---|
| CVE-2026-5366 Vendor/CVE record |
🔴 Critical 2026‑06‑20 |
|
Deployment pull steps accepted unsafe Git commit and sparse-checkout directory arguments. A user permitted to create deployments could execute commands on the worker host, with additional exposure where work pools were shared. | |
Versions, credits, and sourcesReported and CVE-assigned through huntr. CVE CNA: CVSS 3.0 9.9. CNA version record — prefecthq/prefect: affected: unspecified ≤ latest. Standalone finding; excluded from GitHub advisory statistics. | |
| ↑ | |
|---|---|
| Merged patch | 2026-05-27 merged |
|
Malformed UTF-8 length validation bypass | |
Credit and sourcesMerged patch: PR merged. Checked 2026-09-06. | |
| ↑ | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-35459 GHSA-7gvf-3w72-p2pg |
🟠 High 2026‑04‑02 |
||||||||||||||||||||||||
|
The downloader validated its initial destination but followed redirects without rechecking targets. An authenticated user with ADD permission could fetch internal services or reachable metadata endpoints; returned data was written into the download storage folder. | |||||||||||||||||||||||||
| CVE-2026-35464 GHSA-4744-96p5-mp2j |
🔴 Critical 2026‑04‑02 |
||||||||||||||||||||||||
|
Non-admin users with SETTINGS and ADD permissions could point storage_folder at Flask’s session store and download a crafted serialized session. A subsequent request using that session cookie could execute code in the web process. | |||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-02 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-04. Global severity: 🔴 Critical. GitHub global: CVSS 4.0 9.3; CVSS 3.x 0.0. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 9.3. CNA version record — pyload: affected: <= 0.5.0b3.dev96. Incomplete fix: CVE-2026-33992. Redirect targets were not revalidated by the SSRF filter. Coverage: SANS AtRisk XXVI-14. Maintainer advisory · Published 2026-04-02 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-04. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.5. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-502, CWE-863. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.5. CNA version record — pyload: affected: <= 0.5.0b3.dev96. Incomplete fix: CVE-2026-33509. | |||||||||||||||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40260 GHSA-3crg-w4f6-42mx |
🟡 Moderate 2026‑04‑10 |
||||||||||||
|
PDF XMP parsing processed entity declarations without effective expansion limits. A crafted document could exhaust application memory, but merely opening a PDF was insufficient unless the consuming application also parsed its XMP metadata. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-10 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-10. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.9; CVSS 3.1 5.3. Contributors: kodareef5 (reporter), stefan6419846 (analyst). Maintainer weaknesses: CWE-776. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 6.9. CNA version record — pypdf: affected: < 6.10.0. | |||||||||||||
| ↑ | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-mm2q-qcmx-gw4w | 🟠 High 2026‑04‑25 |
||||||||||||||||||||||||
|
Service-account listing checked the wrong administrative action, and updates omitted an ownership check. A user granted admin:UpdateServiceAccount could enumerate other users’ service-account keys, including root-owned keys, and rotate their secrets. | |||||||||||||||||||||||||
| CVE-2026-40937 GHSA-pfcq-4gjr-6gjm |
🟡 Moderate 2026‑04‑22 |
||||||||||||||||||||||||
|
Notification-target handlers authenticated callers but omitted administrator authorization. A read-only user could overwrite known targets, redirect bucket events to a controlled webhook, and make the server probe internal endpoints through target health checks. | |||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-25 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-05-05. Global severity: 🟠 High. GitHub global: CVSS 4.0 7.4; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-863. Maintainer package records
GitHub global package records
Maintainer advisory · Published 2026-04-22 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-22. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.3. The maintainer and global severity labels differ; this page uses the maintainer’s label. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-862. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 8.3. CNA version record — rustfs: affected: < 1.0.0-alpha.94. | |||||||||||||||||||||||||
| ↑ | |
|---|---|
| Changelog acknowledgement | |
|
Blocked | |
Credit and sourcesChangelog acknowledgement: Thanks to @kodareef5 for identifying the need to block GIT_CONFIG_COUNT environment variables and --template / merge related config. Checked 2026-09-06. | |
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40107 GHSA-w95v-4h65-j455 |
🟠 High 2026‑04‑09 |
||||||||||||
|
Mermaid rendering allowed embedded image URLs to survive sanitization. Opening a crafted note triggered requests; on Windows, a network-share URL could additionally expose the user’s NTLMv2 challenge-response hash through automatic authentication. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-09 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-10. Global severity: 🟠 High. GitHub global: CVSS 4.0 8.7; CVSS 3.x 0.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 8.7. CNA version record — siyuan: affected: < 3.6.4. | |||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| GHSA-vpj5-m56f-8h3f | 🟡 Moderate 2026‑07‑30 |
||||||
|
Repository imports and recurring mirror syncs accepted remote URLs without the existing SSRF validation. A user with a registered SSH key could make the server request loopback, private-network, or metadata endpoints. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-30 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.4. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: tonghuaroot (reporter), 456789TZ (reporter), kodareef5 (reporter), thientd (reporter). Maintainer weaknesses: CWE-918. Maintainer package records
| |||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-fvwj-92vj-fg8c | 🔴 Critical 2026‑08‑05 |
||||||||||||
|
A result-typed WebAssembly if without an else could pass validation despite producing no value. Repeated constructs desynchronized the operand stack, exposing host-memory values and allowing writes into another module’s linear memory. | |||||||||||||
| GHSA-r5f5-cv78-6qv8 | 🟠 High 2026‑07‑27 |
||||||||||||
|
The C host-call trampoline pushed a result even for functions declared void. Guest modules invoking these functions could corrupt operand-stack state; repeated calls advanced the stack beyond its allocation and crashed the process. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-05 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: CVSS 3.1 9.0. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-20. Maintainer package records
Maintainer advisory · Published 2026-07-27 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.2. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-670. Maintainer package records
| |||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-x3ff-w252-2g7j | 🟡 Moderate 2026‑03‑30 |
||||||||||||
|
Ed25519 verification did not enforce the scalar range required for a canonical signature. Anyone holding a valid signature could derive a second valid encoding without the signing key, affecting applications that rely on signature uniqueness. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-03-30 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: no structured CVSS score. GitHub global record · Indexed 2026-04-01. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 5.3. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-347. Maintainer package records
GitHub global package records
| |||||||||||||
| ↑ | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41175 GHSA-4jjr-vmv7-wh4w |
🟠 High 2026‑04‑15 |
|||||||||||||||
|
Query values could resolve into destructive method calls. Minimal Control Panel permissions could enable data deletion; unauthenticated exposure required REST or GraphQL to be explicitly enabled without authentication and with the affected resources exposed. | ||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-15 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 8.1. GitHub global record · Indexed 2026-04-16. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 8.1. Contributors: joshuaalwin (reporter), kodareef5 (reporter). Maintainer weaknesses: CWE-470. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 8.1. CNA version record — cms: affected: < 5.73.20; affected: >= 6.0.0-alpha.1, < 6.13.0. | ||||||||||||||||
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| GHSA-m8q3-73v4-wvg7 | 🟡 Moderate 2026‑08‑10 |
||||||
|
A malicious iSCSI or USB device could inject udev properties through unsanitized SCSI identifiers. The earlier serial-number fix missed equivalent fields, allowing device data to request a systemd unit running as root. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-08-10 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 6.4. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-74. Maintainer package records
Incomplete fix: GHSA-vpfq-8p5f-jcqx. Validation covered | |||||||
| ↑ | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-40161 GHSA-wjxp-xrpv-xpff |
🟠 High 2026‑04‑21 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Git resolver API mode combined a user-supplied server URL with the system-configured Git token when no token parameter was supplied. A tenant able to create TaskRuns could redirect that authenticated request to a controlled server. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVE-2026-40923 GHSA-rx35-6rhx-7858 |
🟡 Moderate 2026‑04‑21 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Volume-mount restrictions compared raw paths without normalization. A Task or TaskRun author could use parent-directory components to mount over protected Tekton locations, allowing replacement of internal results or step scripts. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVE-2026-40938 GHSA-94jr-7pqp-xhcq |
🟠 High 2026‑04‑21 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
The Git resolver passed revision values to git fetch as arguments without separating options. A tenant able to submit ResolutionRequests and predict a pod-local repository path could execute commands and access the resolver’s cluster-wide Secret permissions. Downstream fixes — Downstream propagation of CVE-2026-40938 across OpenShift product lines | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-21 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.7. GitHub global record · Indexed 2026-04-21. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.7. Contributors: kodareef5 (reporter), vdemeester (remediation developer). Maintainer weaknesses: CWE-201. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.7. CNA version record — pipeline: affected: >= 1.0.0, < 1.0.2; affected: >= 1.2.0, < 1.3.4; affected: >= 1.4.0, < 1.6.2; affected: >= 1.7.0, < 1.9.3; affected: >= 1.10.0, < 1.11.1. Maintainer advisory · Published 2026-04-21 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 5.4. GitHub global record · Indexed 2026-04-21. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 5.4. Contributors: kodareef5 (reporter), vdemeester (remediation developer), aThorp96 (remediation reviewer). Maintainer weaknesses: CWE-22. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 5.4. CNA version record — pipeline: affected: >= 1.0.0, < 1.0.2; affected: >= 1.2.0, < 1.3.4; affected: >= 1.4.0, < 1.6.2; affected: >= 1.7.0, < 1.9.3; affected: >= 1.10.0, < 1.11.1. Maintainer advisory · Published 2026-04-21 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.5. GitHub global record · Indexed 2026-04-21. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.5. Contributors: offset (reporter), vdemeester (remediation developer), kodareef5 (finder). Maintainer weaknesses: CWE-88. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.5. CNA version record — pipeline: affected: >= 1.0.0, < 1.0.2; affected: >= 1.2.0, < 1.3.4; affected: >= 1.4.0, < 1.6.2; affected: >= 1.7.0, < 1.9.3; affected: >= 1.10.0, < 1.11.1. Coverage: CVEReports. Downstream fixes: Five errata shipped. Checked 2026-09-06. Sources: RHSA-2026:17546 · RHSA-2026:24359 · RHSA-2026:24484 · RHSA-2026:26519 · RHSA-2026:26538. Downstream fixes; the vendor CVE acknowledgement field does not name a reporter. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ↑ | ||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-41263 GHSA-6x2q-h3cr-8j2h |
🟡 Moderate 2026‑04‑24 |
|||||||||||||||||||||
|
The earlier BasicAuth timing fix resolved its fallback secret to an empty string, avoiding the intended bcrypt work. Repeated authentication timing measurements could distinguish registered usernames from nonexistent ones on a reachable protected route. | ||||||||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-04-24 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 4.0 6.3. GitHub global record · Indexed 2026-04-24. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 6.3; CVSS 3.1 3.7. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-208. Maintainer package records
GitHub global package records
CVE CNA: CVSS 4.0 6.3. CNA version record — traefik: affected: < 2.11.43; affected: >= 3.0.0-beta1, < 3.6.14; affected: >= 3.7.0-ea.1, < 3.7.0-rc.2. Incomplete fix: CVE-2026-32595. The fallback secret remained empty, so the intended bcrypt timing mitigation was ineffective. | ||||||||||||||||||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GHSA-qp9x-wp8f-qgjj | 🟡 Moderate 2026‑05‑18 |
||||||||||||
|
Delegation glob matching used platform-dependent case normalization. On Windows, an attacker controlling a delegated role could exploit a case-colliding pattern visited first to serve targets intended for another delegation; POSIX matching was unaffected. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-05-18 · Checked 2026-09-06 Maintainer severity: 🟡 Moderate. Maintainer: CVSS 3.1 4.0. GitHub global record · Indexed 2026-05-28. Global severity: 🟡 Moderate. GitHub global: CVSS 4.0 0.0; CVSS 3.1 4.0. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-178. Maintainer package records
GitHub global package records
| |||||||||||||
| ↑ | |
|---|---|
| Merged patch | 2026-03-29 committed |
|
Correct the vim_fgets() size bound in patch 9.2.0271; follow-up in 9.2.0272 | |
Credit and sourcesMerged patch: Authored by kodareef5. Checked 2026-09-06. | |
| ↑ | |||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-53445 GHSA-7w2h-g83c-jqrp |
🟠 High 2026‑05‑30 |
||||||
|
The copyBoard method did not verify board membership or administrator rights. A logged-in user could copy a private board and its cards and checklists, then make the resulting copy public through supplied properties. | |||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-05-30 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter). Maintainer weaknesses: CWE-862. Maintainer package records
CVE CNA: CVSS 4.0 7.1. CNA version record — wekan: affected: < 9.32. | |||||||
| ↑ | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-77308 GHSA-ggg4-v8vp-jxqh |
🔴 Critical 2026‑07‑10 |
||||||||||||
|
Witness automatically loaded repository-local configuration before commands. An untrusted pull request could redirect attestation uploads and disable sensitive-variable filtering, exposing environment secrets available to a CI job that ran witness on that checkout. | |||||||||||||
| GHSA-88v8-jcjq-95w5 | 🟠 High 2026‑07‑10 |
||||||||||||
|
Certificate-loading code assigned intermediate certificates to the root pool instead of the intermediate pool. Verification failed for affected intermediate-CA hierarchies; deployments using certificates signed directly by a configured root were unaffected. | |||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-07-10 · Checked 2026-09-06 Maintainer severity: 🔴 Critical. Maintainer: no structured CVSS score. CVSS: no structured score available from the checked sources. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter), jkjell (remediation developer). Maintainer weaknesses: CWE-15. Maintainer package records
Verification note: the advisory supplies this CVE identifier, but its public CVE JSON was not retrievable at the 2026-09-06 check. Maintainer advisory · Published 2026-07-10 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: no structured CVSS score. CVSS: no structured score available from the checked sources. Not found in GitHub’s global advisory database at the 2026-09-06 lookup. Contributors: kodareef5 (reporter), jkjell (remediation developer). Maintainer weaknesses: CWE-296. Maintainer package records
| |||||||||||||
| ↑ | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-55672 GHSA-xqxv-4jc2-x56x |
🟠 High 2026‑06‑17 |
|||||||||||||||
|
Authorization-code exchange and token refresh did not bind the grant to its original client. An attacker who obtained a code or refresh token through a separate flaw could redeem it under another client, including across tenants. | ||||||||||||||||
Versions, credits, and sourcesMaintainer advisory · Published 2026-06-17 · Checked 2026-09-06 Maintainer severity: 🟠 High. Maintainer: CVSS 3.1 7.4. GitHub global record · Indexed 2026-06-18. Global severity: 🟠 High. GitHub global: CVSS 4.0 0.0; CVSS 3.1 7.4. Contributors: kodareef5 (reporter), grvijayan (remediation developer), IAM-marco (remediation reviewer), livio-a (other), cipher-creator (reporter), N008x (reporter). Maintainer weaknesses: CWE-287, CWE-863. Maintainer package records
GitHub global package records
CVE CNA: CVSS 3.1 7.4. CNA version record — zitadel: affected: >= 4.0.0-rc.1, < 4.15.2; affected: < 3.4.12. | ||||||||||||||||
Advisory counts cover published GitHub advisories with structured credit. Vendor/CVE-only findings, prose acknowledgements, and patches are separate records.
Repository publication dates and maintainer severity labels are used throughout. CVSS versions, source-specific ratings, package fixes, and contributor roles appear under each project. Undated acknowledgements follow dated work; verification dates are not publication dates.
47 advisories were found in GitHub’s global database; 23 were not found there and are linked to their repository publications. These are lookup results, not a claim that repository advisories are private.
Distributions and verification notes
Advisory-only distributions. A record may name multiple weaknesses; these tables are independent.
| Severity | Advisories |
|---|---|
| 🔴 Critical | 9 |
| 🟠 High | 32 |
| 🟡 Moderate | 24 |
| 🔵 Low | 5 |
Editorial grouping by the affected implementation; not inferred from the logo.
| Language / ecosystem | Advisories |
|---|---|
| Go | 35 |
| JavaScript | 11 |
| Python | 9 |
| Rust | 7 |
| PHP | 5 |
| C++ | 2 |
| C | 1 |
| Weakness | Advisories |
|---|---|
| CWE-918 — Server-Side Request Forgery (SSRF) | 9 |
| CWE-863 — Incorrect Authorization | 7 |
| CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 5 |
| CWE-862 — Missing Authorization | 5 |
| CWE-20 — Improper Input Validation | 3 |
| CWE-287 — Improper Authentication | 3 |
| CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 3 |
| CWE-178 — Improper Handling of Case Sensitivity | 2 |
| CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor | 2 |
| CWE-208 — Observable Timing Discrepancy | 2 |
| CWE-296 — Improper Following of a Certificate's Chain of Trust | 2 |
| CWE-347 — Improper Verification of Cryptographic Signature | 2 |
| CWE-1188 — Initialization of a Resource with an Insecure Default | 1 |
| CWE-122 — Heap-based Buffer Overflow | 1 |
| CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine | 1 |
| CWE-15 — External Control of System or Configuration Setting | 1 |
| CWE-183 — Permissive List of Allowed Inputs | 1 |
| CWE-184 — Incomplete List of Disallowed Inputs | 1 |
| CWE-190 — Integer Overflow or Wraparound | 1 |
| CWE-201 — Insertion of Sensitive Information Into Sent Data | 1 |
| CWE-248 — Uncaught Exception | 1 |
| CWE-269 — Improper Privilege Management | 1 |
| CWE-285 — Improper Authorization | 1 |
| CWE-306 — Missing Authentication for Critical Function | 1 |
| CWE-312 — Cleartext Storage of Sensitive Information | 1 |
| CWE-345 — Insufficient Verification of Data Authenticity | 1 |
| CWE-400 — Uncontrolled Resource Consumption | 1 |
| CWE-426 — Untrusted Search Path | 1 |
| CWE-470 — Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 1 |
| CWE-476 — NULL Pointer Dereference | 1 |
| CWE-502 — Deserialization of Untrusted Data | 1 |
| CWE-59 — Improper Link Resolution Before File Access ('Link Following') | 1 |
| CWE-601 — URL Redirection to Untrusted Site ('Open Redirect') | 1 |
| CWE-613 — Insufficient Session Expiration | 1 |
| CWE-670 — Always-Incorrect Control Flow Implementation | 1 |
| CWE-73 — External Control of File Name or Path | 1 |
| CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | 1 |
| CWE-754 — Improper Check for Unusual or Exceptional Conditions | 1 |
| CWE-770 — Allocation of Resources Without Limits or Throttling | 1 |
| CWE-776 — Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | 1 |
| CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | 1 |
| CWE-94 — Improper Control of Generation of Code ('Code Injection') | 1 |
| Not specified | 5 |
The published advisories supply CVE-2026-35511, CVE-2026-9316, CVE-2026-77308, CVE-2026-73549, CVE-2026-55701, but their public CVE JSON was unavailable at the recorded checks. Their IDs are retained with source-specific notes.
Lyrie Research: Page could not be retrieved during the September 6 review; retained from the earlier record.
See record review for the factual corrections and source policy.
Advisories · Source snapshots · Upstream work · Upstream provenance · Standalone sources · Editorial data · Project marks



