Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-wvm9-9g5j-623f
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

    Published
    10 Sept 2026
    GHSA-w4v4-9rw7-5326
    Fix available
    Packages

    github.com/traefik/traefik/v3, github.com/traefik/traefik/v2

    Summary

    Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

    Published
    10 Sept 2026
    GHSA-v67p-phpq-fc8x
    Fix available
    Packages

    github.com/traefik/traefik/v3

    Summary

    Traefik entrypoint header-name sanitization bypassed via request trailers

    Published
    10 Sept 2026
    GHSA-qqjf-53cj-pwvv
    Fix available
    Packages

    github.com/traefik/traefik/v3, github.com/traefik/traefik/v2

    Summary

    Traefik HTTP/3 Backend NTLM Connection Reuse

    Published
    10 Sept 2026
    GHSA-f52w-8j3h-j724
    Fix available
    Packages

    github.com/traefik/traefik/v3, github.com/traefik/traefik/v2

    Summary

    Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

    Published
    10 Sept 2026
    GHSA-66hp-wgxq-6f5q
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

    Published
    10 Sept 2026
    GHSA-486v-q2wf-fp2r
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone: http backend forwards custom/auth headers to a different host on redirect

    Published
    10 Sept 2026
    GHSA-f8g7-2xjc-7mfh
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

    Published
    10 Sept 2026
    GHSA-p6m2-r3w9-mpxw
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone local: crafted Range request against a translated symlink panics (DoS)

    Published
    10 Sept 2026
    GHSA-xwwr-4h3p-r22c
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

    Published
    10 Sept 2026
    GHSA-p569-5gjg-9cmj
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone: RC per-server auth-proxy bypass

    Published
    10 Sept 2026
    GHSA-c476-6w5q-jw77
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone: FTP cross-session auth-proxy backend confusion

    Published
    10 Sept 2026
    GHSA-38xv-hf3p-h7mq
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone: source object names can escape the configured root on upload

    Published
    10 Sept 2026
    GHSA-2p48-j3qc-rx9f
    Fix available
    Packages

    github.com/rclone/rclone

    Summary

    rclone: S3 multipart declared-length memory exhaustion

    Published
    10 Sept 2026
    GHSA-3g9q-v48f-hh9w
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

    Published
    10 Sept 2026
    GHSA-v39v-59xw-j98g
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

    Published
    10 Sept 2026
    GHSA-8r35-5x5r-hv74
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

    Published
    10 Sept 2026
    GHSA-wjwr-xfp9-r66p
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

    Published
    10 Sept 2026
    GHSA-4qpv-39hg-f7fx
    No fix available
    Packages

    @jhb.software/payload-alt-text-plugin

    Summary

    @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission

    Published
    10 Sept 2026
    GHSA-4x45-gxvp-6283
    Fix available
    Packages

    @argos-ci/core

    Summary

    @argos-ci/core: CI Branch Name OS Command Injection

    Published
    10 Sept 2026
    GHSA-m3wp-48jr-vr4g
    Fix available
    Packages

    mistralrs-server-core

    Summary

    mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS

    Published
    10 Sept 2026
    GHSA-wfgq-w7cq-qj7j
    Fix available
    Packages

    mistralrs-server-core

    Summary

    mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

    Published
    10 Sept 2026
    ECHO-88ec-e122-3747
    No fix available
    Packages

    libxml2

    Summary

    Published
    10 Sept 2026
    GHSA-p78m-89r6-pgf7
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

    Published
    10 Sept 2026
    GHSA-wpmr-8h3q-fwj7
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

    Published
    10 Sept 2026
    GHSA-hf57-cqmx-p4gr
    No fix available
    Packages

    omniroute

    Summary

    OmniRoute ACP Custom-Agent Remote Code Execution (RCE)

    Published
    10 Sept 2026
    GHSA-cw9w-vv67-hf73
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

    Published
    10 Sept 2026
    GHSA-q5wm-mgqx-fv2f
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

    Published
    10 Sept 2026
    GHSA-qgpw-8g46-w95v
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read

    Published
    10 Sept 2026
    GHSA-cqr2-h44g-v75v
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

    Published
    10 Sept 2026
    GHSA-pq6c-vh67-xpm3
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

    Published
    10 Sept 2026
    GHSA-pf83-w3f9-8m37
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions

    Published
    10 Sept 2026
    GHSA-5m98-cgcr-xx3q
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open

    Published
    10 Sept 2026
    GHSA-f2cp-m7mv-8jpv
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

    Published
    10 Sept 2026
    GHSA-679f-58pq-4v2c
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service

    Published
    10 Sept 2026
    GHSA-65xw-2v52-jhxc
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter

    Published
    10 Sept 2026
    MINI-9f8w-qjjr-6mvg
    No fix available
    Packages

    teleport-16

    Summary

    Published
    10 Sept 2026
    MINI-2p36-4rh2-xrh3
    No fix available
    Packages

    plural-agent-harness-0.6-fips

    Summary

    Published
    10 Sept 2026
    MINI-m58q-xmxx-3jmw
    No fix available
    Packages

    plural-agent-harness-0.6

    Summary

    Published
    10 Sept 2026
    MINI-rpjx-wfq2-mpv4
    No fix available
    Packages

    paketo-buildpacks-yarn-install

    Summary

    Published
    10 Sept 2026
    MINI-8gmr-32pg-rg5c
    No fix available
    Packages

    paketo-buildpacks-yarn

    Summary

    Published
    10 Sept 2026
    MINI-f5v7-7rgp-wm4q
    No fix available
    Packages

    paketo-buildpacks-vsdbg

    Summary

    Published
    10 Sept 2026
    MINI-r3cj-pg8v-x3cc
    No fix available
    Packages

    paketo-buildpacks-python-package-managers-run

    Summary

    Published
    10 Sept 2026
    MINI-8396-q77v-795j
    No fix available
    Packages

    paketo-buildpacks-python-package-managers-install

    Summary

    Published
    10 Sept 2026
    MINI-7344-6mmw-2wjp
    No fix available
    Packages

    paketo-buildpacks-poetry-install

    Summary

    Published
    10 Sept 2026
    MINI-qgg4-3cfw-6x7h
    No fix available
    Packages

    paketo-buildpacks-poetry

    Summary

    Published
    10 Sept 2026
    MINI-2g5p-3cg4-6rcm
    No fix available
    Packages

    paketo-buildpacks-pipenv-install

    Summary

    Published
    10 Sept 2026
    MINI-v322-65wc-cq4h
    No fix available
    Packages

    paketo-buildpacks-pipenv

    Summary

    Published
    10 Sept 2026
    MINI-pqgf-3j33-rj4c
    No fix available
    Packages

    paketo-buildpacks-pip-install

    Summary

    Published
    10 Sept 2026
    MINI-6h3f-c2j6-4rw2
    No fix available
    Packages

    paketo-buildpacks-pip

    Summary

    Published
    10 Sept 2026