Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-gh2h-rhph-h37g
    Fix available
    Packages

    Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64

    Summary

    Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    GHSA-8mpw-7fpc-4gqj
    Fix available
    Packages

    nltk

    Summary

    NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

    Published
    8 Sept 2026
    GHSA-w3v8-gmh9-3wv7
    Fix available
    Packages

    nltk

    Summary

    NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

    Published
    8 Sept 2026
    GHSA-rrv8-h7p8-rx55
    Fix available
    Packages

    nltk

    Summary

    NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

    Published
    8 Sept 2026
    GHSA-92f5-vc22-8j33
    Fix available
    Packages

    Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel, Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel

    Summary

    Microsoft QUIC: Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    BELL-CVE-2026-53495
    Fix available
    Packages

    containerd, containerd

    Summary

    Published
    8 Sept 2026
    GHSA-23fw-v26w-5fgq
    Fix available
    Packages

    Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git

    Summary

    Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability

    Published
    8 Sept 2026
    GHSA-7m6h-x95x-82q5
    Fix available
    Packages

    vllm

    Summary

    vLLM: Cross-User Data Leak Vulnerability

    Published
    8 Sept 2026
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    CVE-2026-81192
    Fix available
    Packages

    Summary

    OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-85630
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-85485
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-85484
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    UBUNTU-CVE-2026-19872
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    CVE-2026-85630
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method

    Published
    8 Sept 2026
    CVE-2026-85485
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping

    Published
    8 Sept 2026
    CVE-2026-85484
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping

    Published
    8 Sept 2026
    CVE-2026-19872
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message

    Published
    8 Sept 2026
    CVE-2026-86810
    Fix available
    Packages

    Summary

    Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication

    Published
    8 Sept 2026
    CVE-2026-86464
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    GHSA-3wxw-xv34-2frg
    Fix available
    Packages

    gitpython

    Summary

    GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

    Published
    8 Sept 2026
    CVE-2026-84942
    Fix available
    Packages

    Summary

    Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

    Published
    8 Sept 2026
    CGA-m9cq-xpqr-pgpw
    Fix available
    Packages

    elastic-agent-fips-9.5

    Summary

    Published
    8 Sept 2026
    CVE-2026-86808
    Fix available
    Packages

    Summary

    moltis-org moltis vault.rs vault_recovery_handler missing authentication

    Published
    8 Sept 2026
    CGA-5cc7-h98x-wprf
    Fix available
    Packages

    gitlab-elasticsearch-indexer

    Summary

    Published
    8 Sept 2026
    CVE-2026-86806
    Fix available
    Packages

    Summary

    opengeos GeoLibre _is_within_roots server-side request forgery

    Published
    8 Sept 2026
    CVE-2026-86804
    Fix available
    Packages

    Summary

    seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization

    Published
    8 Sept 2026
    CVE-2026-86716
    No fix available
    Packages

    Summary

    Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow

    Published
    8 Sept 2026
    CGA-q96j-gpmv-qpgq
    Fix available
    Packages

    elastic-agent-fips-9.5

    Summary

    Published
    8 Sept 2026
    GHSA-8mcc-hrx5-hvxc
    Fix available
    Packages

    gitpython

    Summary

    GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

    Published
    8 Sept 2026
    GHSA-5xxx-qhh7-9287
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

    Published
    8 Sept 2026
    GHSA-284h-m62q-gf8w
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

    Published
    8 Sept 2026
    Packages

    @astrojs/prism, @astrojs/webapi, astro, create-astro

    Summary

    TuxCare security update for 4 packages (1 CVE)

    Published
    8 Sept 2026
    GHSA-7833-fr7j-v32q
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

    Published
    8 Sept 2026
    GHSA-4qhr-qf46-fcrx
    Fix available
    Packages

    Microsoft.DiaSymReader.Native

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    GHSA-q72m-f2r4-w4cw
    Fix available
    Packages

    Microsoft.DiaSymReader.Native

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    GHSA-mqvm-gmc4-6rv2
    Fix available
    Packages

    Microsoft.DiaSymReader.Native

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

    Published
    8 Sept 2026
    GHSA-v3f6-m9j2-437p
    Fix available
    Packages

    Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

    Published
    8 Sept 2026
    USN-8739-1
    Fix available
    Packages

    imagemagick, imagemagick, imagemagick, imagemagick, imagemagick, imagemagick

    Summary

    imagemagick vulnerabilities

    Published
    8 Sept 2026
    CVE-2026-84003
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-83948
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81383
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81381
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81379
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81378
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81377
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81376
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026