Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-vr34-hp96-76pp
    Fix available
    Packages

    @xmldom/xmldom

    Summary

    xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator

    Published
    8 Sept 2026
    GHSA-6h8r-xr42-gp59
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content

    Published
    8 Sept 2026
    GHSA-8344-3jmq-59r6
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Quadratic-time attribute deduplication

    Published
    8 Sept 2026
    GHSA-x4fp-j954-r2f4
    Fix available
    Packages

    @xmldom/xmldom

    Summary

    xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser

    Published
    8 Sept 2026
    GHSA-965w-775f-mr7g
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Quadratic-memory consumption

    Published
    8 Sept 2026
    GHSA-93r5-fhx6-vmg9
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge

    Published
    8 Sept 2026
    GHSA-6mj3-qw4j-hgrw
    Fix available
    Packages

    @xmldom/xmldom

    Summary

    xmldom: HTML raw-text closing-tag case mismatch causes output amplification

    Published
    8 Sept 2026
    GHSA-w6f5-v2h6-g786
    Fix available
    Packages

    predis/predis

    Summary

    Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

    Published
    8 Sept 2026
    GHSA-fxf7-vhh8-7vpq
    Fix available
    Packages

    cakephp/cakephp, cakephp/cakephp, cakephp/cakephp, cakephp/database, cakephp/database, cakephp/database

    Summary

    CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver

    Published
    8 Sept 2026
    GHSA-2qh5-382h-3jpc
    Fix available
    Packages

    cakephp/cakephp, cakephp/cakephp, cakephp/cakephp, cakephp/cakephp, cakephp/cakephp

    Summary

    CakePHP: SmtpTransport vulnerable to CRLF header injection

    Published
    8 Sept 2026
    GHSA-6w3j-5fw6-r9vr
    Fix available
    Packages

    joi, @hapi/joi, joi

    Summary

    joi: Prototype pollution via a `__proto__` language key in custom messages

    Published
    8 Sept 2026
    GHSA-2wm5-q62r-hmrv
    Fix available
    Packages

    colord

    Summary

    Colord: Slow rejection of oversized malformed color strings

    Published
    8 Sept 2026
    GHSA-p293-qw3h-jr36
    Fix available
    Packages

    next, next

    Summary

    Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

    Published
    8 Sept 2026
    GHSA-gg4h-3hg2-grpc
    Fix available
    Packages

    joi, joi

    Summary

    joi: object().rename() with a template target can set the validated object's prototype

    Published
    8 Sept 2026
    GHSA-jrc7-96c5-q579
    Fix available
    Packages

    maplibre-gl

    Summary

    MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip

    Published
    8 Sept 2026
    GHSA-qc2q-p7wx-3px3
    Fix available
    Packages

    google.golang.org/grpc

    Summary

    gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion

    Published
    8 Sept 2026
    GHSA-8xx6-hgc6-gc2m
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

    Published
    8 Sept 2026
    DEBIAN-CVE-2026-79604
    No fix available
    Packages

    xen, xen, xen

    Summary

    Published
    8 Sept 2026
    GHSA-82fw-gwwq-j7x9
    Fix available
    Packages

    @vitest/mocker, vitest, vitest, @vitest/mocker

    Summary

    Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock

    Published
    8 Sept 2026
    GHSA-pf96-p4fj-6566
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

    Published
    8 Sept 2026
    GHSA-h4x7-gw46-3wm6
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

    Published
    8 Sept 2026
    GHSA-f2fp-rgf2-35cp
    Fix available
    Packages

    httpx2

    Summary

    HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

    Published
    8 Sept 2026
    GHSA-7mj9-2mp8-4m2p
    Fix available
    Packages

    httpcore2, httpx2

    Summary

    HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

    Published
    8 Sept 2026
    GHSA-4hhp-h66f-j5j7
    Fix available
    Packages

    vllm

    Summary

    vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

    Published
    8 Sept 2026
    GHSA-c7r6-vx3h-w5g2
    Fix available
    Packages

    maatwebsite/excel

    Summary

    Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path

    Published
    8 Sept 2026
    CGA-hqg7-89fg-84p8
    Fix available
    Packages

    gitlab-elasticsearch-indexer-fips

    Summary

    Published
    8 Sept 2026
    CGA-89hq-rm9f-3gg3
    Fix available
    Packages

    gitlab-elasticsearch-indexer

    Summary

    Published
    8 Sept 2026
    GHSA-g53g-w8rj-fmg7
    Fix available
    Packages

    @xmldom/xmldom

    Summary

    xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions

    Published
    8 Sept 2026
    GHSA-w2rr-34g9-rvrj
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Element name injection via createElement() bypasses requireWellFormed

    Published
    8 Sept 2026
    GHSA-4w3w-2rp5-g8jm
    Fix available
    Packages

    @xmldom/xmldom, @xmldom/xmldom, xmldom

    Summary

    xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed

    Published
    8 Sept 2026
    GHSA-gh2h-rhph-h37g
    Fix available
    Packages

    Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64

    Summary

    Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    GHSA-8mpw-7fpc-4gqj
    Fix available
    Packages

    nltk

    Summary

    NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

    Published
    8 Sept 2026
    GHSA-w3v8-gmh9-3wv7
    Fix available
    Packages

    nltk

    Summary

    NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

    Published
    8 Sept 2026
    GHSA-rrv8-h7p8-rx55
    Fix available
    Packages

    nltk

    Summary

    NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

    Published
    8 Sept 2026
    GHSA-92f5-vc22-8j33
    Fix available
    Packages

    Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel, Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel

    Summary

    Microsoft QUIC: Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    BELL-CVE-2026-53495
    Fix available
    Packages

    containerd

    Summary

    Published
    8 Sept 2026
    GHSA-23fw-v26w-5fgq
    Fix available
    Packages

    Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git, Microsoft.SourceLink.AzureRepos.Git

    Summary

    Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability

    Published
    8 Sept 2026
    GHSA-7m6h-x95x-82q5
    Fix available
    Packages

    vllm

    Summary

    vLLM: Cross-User Data Leak Vulnerability

    Published
    8 Sept 2026
    DEBIAN-CVE-2026-85630
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    DEBIAN-CVE-2026-85485
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    DEBIAN-CVE-2026-85484
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    CVE-2026-81192
    Fix available
    Packages

    Summary

    OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS

    Published
    8 Sept 2026
    DEBIAN-CVE-2026-19872
    No fix available
    Packages

    libhtml-formhandler-perl, libhtml-formhandler-perl, libhtml-formhandler-perl

    Summary

    Published
    8 Sept 2026
    CVE-2026-85630
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method

    Published
    8 Sept 2026
    CVE-2026-85485
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping

    Published
    8 Sept 2026
    CVE-2026-85484
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping

    Published
    8 Sept 2026
    CVE-2026-19872
    Fix available
    Packages

    Summary

    HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message

    Published
    8 Sept 2026
    CVE-2026-86810
    Fix available
    Packages

    Summary

    Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authentication

    Published
    8 Sept 2026
    CVE-2026-86464
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    GHSA-3wxw-xv34-2frg
    Fix available
    Packages

    gitpython

    Summary

    GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

    Published
    8 Sept 2026