Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection Moderate
GHSA-w253-m66g-rx24 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection Moderate
GHSA-5gj4-9gm7-2fx2 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Envoy: HTTP - filter chain execution on reset streams causing UAF crash Moderate
CVE-2026-26311 was published for github.com/envoyproxy/envoy (Go) Mar 10, 2026
MushroomWasp Credited to MushroomWasp, agrawroh, yanavlasov, botengyao, and phlax agrawroh agrawroh
yanavlasov yanavlasov botengyao botengyao phlax phlax
Werkzeug safe_join() allows Windows special device names with compound extensions Moderate
CVE-2026-21860 was published for Werkzeug (pip) Jan 8, 2026
yueyueL Credited to yueyueL and MushroomWasp MushroomWasp MushroomWasp
ProTip! Advisories are also available from the GraphQL API