GitHub Advisories

topic · security/github-advisories
DOC.
security/github-advisories
REV.
1,982 evt
DATE.
03-JUN-2026
§01

about

Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing the 10 most recent of 1,982 total events on this topic. apply a date range to scope the list.

range
iso 8601 utc
iso 8601 utc
01CRITICAL: AWS Amplify Studio UI Component Properties Has an Input Validation Issuecritical severity · @aws-amplify/codegen-ui-react · CVE-2025-4318{"cve":"CVE-2025-4318","url":"https://github.com/advisories/GHSA-hf3j-86p7-mfw8"…
EVENT. cms80hqqID. cms80hqqqb279kh0cl31czcpjSRC. key:cmpxakb6
{
  "cve": "CVE-2025-4318",
  "url": "https://github.com/advisories/GHSA-hf3j-86p7-mfw8",
  "cwes": [
    "CWE-95"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-hf3j-86p7-mfw8",
  "summary": "AWS Amplify Studio UI Component Properties Has an Input Validation Issue",
  "severity": "critical",
  "cvss_score": null,
  "ecosystems": [
    "npm"
  ],
  "references": [
    "https://github.com/aws-amplify/amplify-codegen-ui/security/advisories/GHSA-hf3j-86p7-mfw8",
    "https://nvd.nist.gov/vuln/detail/CVE-2025-4318",
    "https://github.com/aws-amplify/amplify-codegen-ui/commit/ca98c38b7c3d69ae7c94d2f62b51e32e8165dae6",
    "https://aws.amazon.com/security/security-bulletins/AWS-2025-010",
    "https://blog.securelayer7.net/cve-2025-4318-aws-amplify-rce"
  ],
  "updated_at": "2026-07-30T20:57:25.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T20:57:24.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "@aws-amplify/codegen-ui-react",
      "ecosystem": "npm",
      "first_patched": "2.20.3",
      "vulnerable_range": "<= 2.20.2"
    }
  ]
}
02CRITICAL: Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processingcritical severity · activestorage, activestorage, activestorage · CVE-2026-66066{"cve":"CVE-2026-66066","url":"https://github.com/advisories/GHSA-xr9x-r78c-5hrm…
EVENT. cms7w7k1ID. cms7w7k1eb0x9kh0cy997qoumSRC. key:cmpxakb6
{
  "cve": "CVE-2026-66066",
  "url": "https://github.com/advisories/GHSA-xr9x-r78c-5hrm",
  "cwes": [
    "CWE-1188"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-xr9x-r78c-5hrm",
  "summary": "Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing",
  "severity": "critical",
  "cvss_score": null,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm",
    "https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e",
    "https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5",
    "https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a",
    "https://github.com/rails/rails/releases/tag/v7.2.3.2"
  ],
  "updated_at": "2026-07-30T18:23:34.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T18:23:33.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "activestorage",
      "ecosystem": "rubygems",
      "first_patched": "7.2.3.2",
      "vulnerable_range": "< 7.2.3.2"
    },
    {
      "name": "activestorage",
      "ecosystem": "rubygems",
      "first_patched": "8.0.5.1",
      "vulnerable_range": ">= 8.0.0.beta1, < 8.0.5.1"
    },
    {
      "name": "activestorage",
      "ecosystem": "rubygems",
      "first_patched": "8.1.3.1",
      "vulnerable_range": ">= 8.1.0.beta1, < 8.1.3.1"
    }
  ]
}
03HIGH: dssrf has an SSRF bypass with remove_at_symbol_in_stringhigh severity · dssrf · CVE-2026-54722{"cve":"CVE-2026-54722","url":"https://github.com/advisories/GHSA-cg4g-m8jx-vjv2…
EVENT. cms7rx2hID. cms7rx2h8azpxkh0c28n6ebwaSRC. key:cmpxakb6
{
  "cve": "CVE-2026-54722",
  "url": "https://github.com/advisories/GHSA-cg4g-m8jx-vjv2",
  "cwes": [
    "CWE-76"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-cg4g-m8jx-vjv2",
  "summary": "dssrf has an SSRF bypass with remove_at_symbol_in_string",
  "severity": "high",
  "cvss_score": null,
  "ecosystems": [
    "npm"
  ],
  "references": [
    "https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-cg4g-m8jx-vjv2",
    "https://github.com/HackingRepo/dssrf-js/issues/97",
    "https://github.com/HackingRepo/dssrf-js/pull/98",
    "https://github.com/HackingRepo/dssrf-js/commit/9211f91bf532433a1a1b27d946571546a63664b3",
    "https://github.com/advisories/GHSA-cg4g-m8jx-vjv2"
  ],
  "updated_at": "2026-07-30T16:26:54.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T16:26:52.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "dssrf",
      "ecosystem": "npm",
      "first_patched": "1.0.4",
      "vulnerable_range": "<= 1.0.3"
    }
  ]
}
04LOW: MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosurelow severity · msgpack · CVE-2026-54522{"cve":"CVE-2026-54522","url":"https://github.com/advisories/GHSA-4mrv-5p47-p938…
EVENT. cms7rx1vID. cms7rx1v9azptkh0cs871r5cqSRC. key:cmpxakb6
{
  "cve": "CVE-2026-54522",
  "url": "https://github.com/advisories/GHSA-4mrv-5p47-p938",
  "cwes": [
    "CWE-416"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-4mrv-5p47-p938",
  "summary": "MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure",
  "severity": "low",
  "cvss_score": null,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938",
    "https://github.com/msgpack/msgpack-ruby/commit/5627d71606b565641d2dd501b82aae862f4abe90",
    "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/msgpack/CVE-2026-54522.yml",
    "https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-54522",
    "https://github.com/advisories/GHSA-4mrv-5p47-p938"
  ],
  "updated_at": "2026-07-30T16:33:13.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T16:33:12.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "msgpack",
      "ecosystem": "rubygems",
      "first_patched": "1.8.2",
      "vulnerable_range": "<= 1.8.1"
    }
  ]
}
05HIGH: OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)high severity · github.com/OliveTin/OliveTin · CVE-2026-67437{"cve":"CVE-2026-67437","url":"https://github.com/advisories/GHSA-xpxj-f2fm-rqch…
EVENT. cms7nn3gID. cms7nn3gzayndkh0c7g3vhedtSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67437",
  "url": "https://github.com/advisories/GHSA-xpxj-f2fm-rqch",
  "cwes": [
    "CWE-400",
    "CWE-401",
    "CWE-770"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-xpxj-f2fm-rqch",
  "summary": "OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)",
  "severity": "high",
  "cvss_score": 7.5,
  "ecosystems": [
    "go"
  ],
  "references": [
    "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67437",
    "https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f",
    "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0",
    "https://github.com/advisories/GHSA-xpxj-f2fm-rqch"
  ],
  "updated_at": "2026-07-30T14:24:55.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "published_at": "2026-07-30T14:24:53.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "github.com/OliveTin/OliveTin",
      "ecosystem": "go",
      "first_patched": "0.0.0-20260708075951-ec114e95d297",
      "vulnerable_range": ">= 0.0.0-20251024001301-45f9c18bc3ee, < 0.0.0-20260708075951-ec114e95d297"
    }
  ]
}
06MEDIUM: OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Outputmedium severity · github.com/OliveTin/OliveTin · CVE-2026-67439{"cve":"CVE-2026-67439","url":"https://github.com/advisories/GHSA-jm28-2wcr-qf3h…
EVENT. cms7nn2xID. cms7nn2xjaynbkh0c6b1v4hvqSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67439",
  "url": "https://github.com/advisories/GHSA-jm28-2wcr-qf3h",
  "cwes": [
    "CWE-863"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-jm28-2wcr-qf3h",
  "summary": "OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output",
  "severity": "medium",
  "cvss_score": 4.3,
  "ecosystems": [
    "go"
  ],
  "references": [
    "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-jm28-2wcr-qf3h",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67439",
    "https://github.com/OliveTin/OliveTin/commit/e421780c9885aa5024d2f47b4ed4898f2f18eb90",
    "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0",
    "https://github.com/advisories/GHSA-jm28-2wcr-qf3h"
  ],
  "updated_at": "2026-07-30T14:25:21.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "published_at": "2026-07-30T14:25:20.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "github.com/OliveTin/OliveTin",
      "ecosystem": "go",
      "first_patched": "0.0.0-20260708085316-e421780c9885",
      "vulnerable_range": "< 0.0.0-20260708085316-e421780c9885"
    }
  ]
}
07MEDIUM: OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Checkmedium severity · github.com/OliveTin/OliveTin · CVE-2026-67438{"cve":"CVE-2026-67438","url":"https://github.com/advisories/GHSA-xc5w-4v5w-7x65…
EVENT. cms7nn2eID. cms7nn2e9ayn9kh0col303ae1SRC. key:cmpxakb6
{
  "cve": "CVE-2026-67438",
  "url": "https://github.com/advisories/GHSA-xc5w-4v5w-7x65",
  "cwes": [
    "CWE-78"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-xc5w-4v5w-7x65",
  "summary": "OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check",
  "severity": "medium",
  "cvss_score": 6.6,
  "ecosystems": [
    "go"
  ],
  "references": [
    "https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xc5w-4v5w-7x65",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67438",
    "https://github.com/OliveTin/OliveTin/commit/995ff79736f2bccc364448a3ece84087b550b232",
    "https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0",
    "https://github.com/advisories/GHSA-xc5w-4v5w-7x65"
  ],
  "updated_at": "2026-07-30T14:31:15.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "published_at": "2026-07-30T14:31:12.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "github.com/OliveTin/OliveTin",
      "ecosystem": "go",
      "first_patched": "0.0.0-20260708084548-995ff79736f2",
      "vulnerable_range": ">= 0.0.0-20251025234746-ef5a67e7b8ea, < 0.0.0-20260708084548-995ff79736f2"
    }
  ]
}
08MEDIUM: MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protectionmedium severity · mcp · CVE-2026-63118{"cve":"CVE-2026-63118","url":"https://github.com/advisories/GHSA-rjr6-rcgv-9m7m…
EVENT. cms7nn1uID. cms7nn1uwayn7kh0c299xyydrSRC. key:cmpxakb6
{
  "cve": "CVE-2026-63118",
  "url": "https://github.com/advisories/GHSA-rjr6-rcgv-9m7m",
  "cwes": [
    "CWE-346",
    "CWE-350"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-rjr6-rcgv-9m7m",
  "summary": "MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection",
  "severity": "medium",
  "cvss_score": null,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-rjr6-rcgv-9m7m",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-63118",
    "https://github.com/modelcontextprotocol/ruby-sdk/commit/ba543083a7594e7892b29464b89091816446ff7a",
    "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
    "https://github.com/advisories/GHSA-rjr6-rcgv-9m7m"
  ],
  "updated_at": "2026-07-30T14:41:42.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T14:41:39.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "mcp",
      "ecosystem": "rubygems",
      "first_patched": "0.23.0",
      "vulnerable_range": "<= 0.22.0"
    }
  ]
}
09MEDIUM: MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)medium severity · mcp · CVE-2026-63119{"cve":"CVE-2026-63119","url":"https://github.com/advisories/GHSA-7683-3w9x-ch42…
EVENT. cms7nn1bID. cms7nn1bcayn5kh0cqn2eb0k0SRC. key:cmpxakb6
{
  "cve": "CVE-2026-63119",
  "url": "https://github.com/advisories/GHSA-7683-3w9x-ch42",
  "cwes": [
    "CWE-400",
    "CWE-770"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-7683-3w9x-ch42",
  "summary": "MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)",
  "severity": "medium",
  "cvss_score": 6.2,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-7683-3w9x-ch42",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-63119",
    "https://github.com/modelcontextprotocol/ruby-sdk/commit/267b8fa6285453525c81ce43db6b7dcd7a8a8c2f",
    "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
    "https://github.com/advisories/GHSA-7683-3w9x-ch42"
  ],
  "updated_at": "2026-07-30T14:41:58.000Z",
  "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "published_at": "2026-07-30T14:41:58.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "mcp",
      "ecosystem": "rubygems",
      "first_patched": "0.23.0",
      "vulnerable_range": "<= 0.22.0"
    }
  ]
}
10MEDIUM: MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodmedium severity · mcp · CVE-2026-67430{"cve":"CVE-2026-67430","url":"https://github.com/advisories/GHSA-52jp-gj8w-j6xh…
EVENT. cms7nn0rID. cms7nn0rwayn3kh0c1tluceu6SRC. key:cmpxakb6
{
  "cve": "CVE-2026-67430",
  "url": "https://github.com/advisories/GHSA-52jp-gj8w-j6xh",
  "cwes": [
    "CWE-401",
    "CWE-770"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-52jp-gj8w-j6xh",
  "summary": "MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood",
  "severity": "medium",
  "cvss_score": 5.3,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-52jp-gj8w-j6xh",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67430",
    "https://github.com/modelcontextprotocol/ruby-sdk/commit/afb968c468c178c4d3294b423fcce250621692f4",
    "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
    "https://github.com/advisories/GHSA-52jp-gj8w-j6xh"
  ],
  "updated_at": "2026-07-30T14:43:29.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "published_at": "2026-07-30T14:43:29.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "mcp",
      "ecosystem": "rubygems",
      "first_patched": "0.23.0",
      "vulnerable_range": "<= 0.22.0"
    }
  ]
}
showing 1–10 of 1,982older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/github-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above