Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,090 advisories

Loading
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability High
CVE-2026-50525 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability High
CVE-2026-50528 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability High
CVE-2026-50648 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
bribrothers Credited to bribrothers
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability High
CVE-2026-50524 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability High
CVE-2026-47304 was published for System.Security.Cryptography.Xml (NuGet) Jul 20, 2026
rbhanda Credited to rbhanda
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability High
CVE-2026-47302 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
nmas321 Credited to nmas321, MattKilgore, bottarocarlo, and bribrothers MattKilgore MattKilgore
bottarocarlo bottarocarlo bribrothers bribrothers
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability High
CVE-2026-57108 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass Moderate
CVE-2026-54570 was published for AngleSharp (NuGet) Jul 17, 2026
internetpestcontrol Credited to internetpestcontrol
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50273 was published for Datadog.Trace (NuGet) Jul 15, 2026
Umbraco.AI discloses sensitive application configuration values Moderate
GHSA-q3v2-xj35-9grx was published for Umbraco.AI (NuGet) Jul 14, 2026
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding Low
CVE-2026-50268 was published for Steeltoe.Configuration.Encryption (NuGet) Jul 2, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted Moderate
CVE-2026-50267 was published for Steeltoe.Configuration.Abstractions (NuGet) Jul 2, 2026
Steeltoe's static JWKS cache shared across schemes and never invalidated Moderate
CVE-2026-50202 was published for Steeltoe.Security.Authentication.CloudFoundryBase (NuGet) Jul 2, 2026
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission Moderate
CVE-2026-50201 was published for Steeltoe.Management.Endpoint (NuGet) Jul 2, 2026
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords High
CVE-2026-50200 was published for Steeltoe.Management.Endpoint (NuGet) Jul 2, 2026
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch High
CVE-2026-50196 was published for Steeltoe.Discovery.Eureka (NuGet) Jul 2, 2026
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header High
CVE-2026-50194 was published for Steeltoe.Management.Endpoint (NuGet) Jul 2, 2026
sondt99 Credited to sondt99
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing High
CVE-2026-49451 was published for Microsoft.OpenAPI (NuGet) Jun 30, 2026
baywet Credited to baywet, cookesan, Falco20019, and mahsa-lamiyan cookesan cookesan
Falco20019 Falco20019 mahsa-lamiyan mahsa-lamiyan
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image Moderate
CVE-2026-53465 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 26, 2026
007bsd Credited to 007bsd
ImageMagick: Memory Leak in wand option parser when providing invalid arguments Moderate
CVE-2026-53464 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 26, 2026
007bsd Credited to 007bsd
MindflareX Credited to MindflareX and adamus2 adamus2 adamus2
MindflareX Credited to MindflareX and adamus2 adamus2 adamus2
ProTip! Advisories are also available from the GraphQL API