Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

361 advisories

Loading
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass) High
GHSA-46q4-43ph-c6fr was published for org.http4s:blaze-http_2.12 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser High
GHSA-mhvj-jhpq-885v was published for org.http4s:blaze-http_2.13 (Maven) Jul 24, 2026
ERobertGII Credited to ERobertGII and rossabaker rossabaker rossabaker
swift-nio-http2: Missing CR/LF/NUL validation in header values Moderate
CVE-2026-64785 was published for swift-nio-http2 (Swift) Jul 24, 2026
sour-exploit Credited to sour-exploit
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass Moderate
CVE-2026-59900 was published for io.netty:netty-codec-http2 (Maven) Jul 22, 2026
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation Moderate
CVE-2026-59898 was published for io.netty:netty-codec-http (Maven) Jul 22, 2026
mint: Content-Length header accepts non-RFC "+" sign prefix Moderate
CVE-2026-49753 was published for mint (Erlang) Jul 9, 2026
PJUllrich Credited to PJUllrich, ericmj, and maennchen ericmj ericmj
maennchen maennchen
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests High
CVE-2026-50197 was published for github.com/zalando/skipper (Go) Jul 8, 2026
tonghuaroot Credited to tonghuaroot
ProTip! Advisories are also available from the GraphQL API