Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

735 advisories

Loading
Payload authentication token field handling issue Critical
CVE-2026-105863 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control High
CVE-2026-104891 was published for @insumermodel/mppx-condition-gate (npm) Oct 7, 2026
chenshj73 Credited to chenshj73
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write High
CVE-2026-105741 was published for langflow (pip) Oct 7, 2026
erichare Credited to erichare and andifilhohub andifilhohub andifilhohub
dinhvaren Credited to dinhvaren
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions. Moderate Unreviewed
CVE-2026-97308 was published Oct 6, 2026
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions. Moderate Unreviewed
CVE-2026-39772 was published Oct 6, 2026
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions. Moderate Unreviewed
CVE-2026-105057 was published Oct 6, 2026
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet Critical
CVE-2026-90711 was published for proxy-addr (npm) Oct 5, 2026
kagebunsher Credited to kagebunsher, UlisesGascon, and kustundag UlisesGascon UlisesGascon
kustundag kustundag
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions. Moderate Unreviewed
CVE-2026-103347 was published Oct 1, 2026
ProTip! Advisories are also available from the GraphQL API