Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,435 advisories

Loading
Payload didn't enforce field-level password update restrictions High
CVE-2026-105855 was published for payload (npm) Oct 6, 2026
pavelkohout396 Credited to pavelkohout396
Payload: ReDoS in Multipart Content-Type Validation High
CVE-2026-105854 was published for payload (npm) Oct 6, 2026
hwpark6804-gif Credited to hwpark6804-gif
Payload vulnerable to API key disclosure through ordinary document reads High
CVE-2026-105849 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload Ecommerce has an order confirmation validation issue High
CVE-2026-105850 was published for @payloadcms/plugin-ecommerce (npm) Oct 6, 2026
Payload relationship-query authorization bypass Moderate
CVE-2026-105852 was published for payload (npm) Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields High
CVE-2026-105853 was published for payload (npm) Oct 6, 2026
Payload: Field access control bypass on auth collections Critical
CVE-2026-105851 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload: Insufficient Access Control in Stripe REST Proxy Moderate
CVE-2026-105848 was published for @payloadcms/plugin-stripe (npm) Oct 6, 2026
Payload: Improper access control for MCP API keys High
CVE-2026-105806 was published for @payloadcms/plugin-mcp (npm) Oct 6, 2026
pavelkohout396 Credited to pavelkohout396
Payload: Prototype pollution in Payload Import Export plugin Critical
CVE-2026-105844 was published for @payloadcms/plugin-import-export (npm) Oct 6, 2026
iamnoooob Credited to iamnoooob
Payload: SQL Injection in SQLite and Postgres Critical
CVE-2026-105845 was published for payload (npm) Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit Moderate
CVE-2026-105846 was published for @payloadcms/next (npm) Oct 6, 2026
kullai-secasure Credited to kullai-secasure and yuvraj-secasure yuvraj-secasure yuvraj-secasure
Payload: Polymorphic join queries could disclose hidden fields High
CVE-2026-105847 was published for payload (npm) Oct 6, 2026
Payload: Password hashes use insufficient PBKDF2 iterations Moderate
CVE-2026-105804 was published for payload (npm) Oct 6, 2026
georgelzrc Credited to georgelzrc
Payload: Sort queries could expose protected field information Moderate
CVE-2026-105805 was published for payload (npm) Oct 6, 2026
braintxx Credited to braintxx
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests Low
CVE-2026-105795 was published for Microsoft.OpenApi.Kiota (NuGet) Oct 6, 2026
gavinbarron Credited to gavinbarron and adrian05-ms adrian05-ms adrian05-ms
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators High
CVE-2026-105796 was published for Microsoft.OpenApi.Kiota (NuGet) Oct 6, 2026
gavinbarron Credited to gavinbarron
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server High
CVE-2026-104850 was published for @modelcontextprotocol/client (npm) Oct 6, 2026
Aviral2642 Credited to Aviral2642, AlexMelanFromRingo, Gal3m, JosephDoUrden, Igfray, OriginalKazdov, and lwebmedia AlexMelanFromRingo AlexMelanFromRingo
Gal3m Gal3m JosephDoUrden JosephDoUrden Igfray Igfray OriginalKazdov OriginalKazdov lwebmedia lwebmedia
i18next-http-backend incomplete URL validation permits SSRF Low
CVE-2026-105800 was published for i18next-http-backend (npm) Oct 6, 2026
avrlab233 Credited to avrlab233
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL Critical
CVE-2026-105794 was published for Microsoft.Native.Quic.MsQuic.OpenSSL (NuGet) Oct 6, 2026
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation High
CVE-2026-105801 was published for openapi-python-client (pip) Oct 6, 2026
Gal3m Credited to Gal3m, iabdullah215, and 0xsharz iabdullah215 iabdullah215
0xsharz 0xsharz
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values Low
CVE-2026-105799 was published for @langchain/redis (npm) Oct 6, 2026
thesanjok Credited to thesanjok and shovanchakraborty shovanchakraborty shovanchakraborty
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration High
CVE-2026-26287 was published for github.com/external-secrets/external-secrets (Go) Oct 6, 2026
1seal Credited to 1seal, gusfcarvalho, and evrardj-roche gusfcarvalho gusfcarvalho
evrardj-roche evrardj-roche
Vyper: Memory corruption using function calls within tuples / nested calls Moderate
GHSA-2r3x-4mrv-mcxf was published for vyper (pip) Oct 6, 2026
Vyper: Call stack corruption when passing complex type containing non-base type members as argument Moderate
GHSA-4v7v-gqf9-ww2g was published for vyper (pip) Oct 6, 2026
ProTip! Advisories are also available from the GraphQL API