GitHub Advisories

topic · security/github-advisories
DOC.
security/github-advisories
REV.
1,982 evt
DATE.
03-JUN-2026
SCOPE.
custom
§01

about

Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 1,946 events in this window (1,982 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01MEDIUM: veraPDF Parser DoS via PostScript Type 1 Font Programsmedium severity · org.verapdf:parser, org.verapdf:parser · CVE-2026-54081{"cve":"CVE-2026-54081","url":"https://github.com/advisories/GHSA-7c26-995w-6f47…
EVENT. cms6aau1ID. cms6aau1aalhzkh0cb0zqueqzSRC. key:cmpxakb6
{
  "cve": "CVE-2026-54081",
  "url": "https://github.com/advisories/GHSA-7c26-995w-6f47",
  "cwes": [
    "CWE-1325"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-7c26-995w-6f47",
  "summary": "veraPDF Parser DoS via PostScript Type 1 Font Programs",
  "severity": "medium",
  "cvss_score": null,
  "ecosystems": [
    "maven"
  ],
  "references": [
    "https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-7c26-995w-6f47",
    "https://github.com/veraPDF/veraPDF-parser/pull/703",
    "https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce",
    "https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4",
    "https://github.com/advisories/GHSA-7c26-995w-6f47"
  ],
  "updated_at": "2026-07-29T15:19:06.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-29T15:19:04.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "org.verapdf:parser",
      "ecosystem": "maven",
      "first_patched": "1.30.2",
      "vulnerable_range": "<= 1.30.1"
    },
    {
      "name": "org.verapdf:parser",
      "ecosystem": "maven",
      "first_patched": "1.31.23",
      "vulnerable_range": ">= 1.31.1, <= 1.31.22"
    }
  ]
}
02HIGH: Req vulnerable to unbounded archive/compression extraction triggered by response content-typehigh severity · req · CVE-2026-49755{"cve":"CVE-2026-49755","url":"https://github.com/advisories/GHSA-655f-mp8p-96gv…
EVENT. cms6aathID. cms6aath2alhxkh0cly8hj59xSRC. key:cmpxakb6
{
  "cve": "CVE-2026-49755",
  "url": "https://github.com/advisories/GHSA-655f-mp8p-96gv",
  "cwes": [
    "CWE-409"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-655f-mp8p-96gv",
  "summary": "Req vulnerable to unbounded archive/compression extraction triggered by response content-type",
  "severity": "high",
  "cvss_score": null,
  "ecosystems": [
    "erlang"
  ],
  "references": [
    "https://github.com/wojtekmach/req/security/advisories/GHSA-655f-mp8p-96gv",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-49755",
    "https://github.com/wojtekmach/req/commit/84977e5b1a83f26e749d55ad06e3625464af4e8d",
    "https://cna.erlef.org/cves/CVE-2026-49755.html",
    "https://osv.dev/vulnerability/EEF-CVE-2026-49755"
  ],
  "updated_at": "2026-07-29T15:23:18.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-29T15:23:16.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "req",
      "ecosystem": "erlang",
      "first_patched": "0.6.1",
      "vulnerable_range": ">= 0.1.0, < 0.6.1"
    }
  ]
}
03MEDIUM: Req vulnerable to multipart form-data header injection via unescaped name/filename/content_typemedium severity · req · CVE-2026-49756{"cve":"CVE-2026-49756","url":"https://github.com/advisories/GHSA-px9f-whj3-246m…
EVENT. cms6aaswID. cms6aaswdalhtkh0cybjpvpeiSRC. key:cmpxakb6
{
  "cve": "CVE-2026-49756",
  "url": "https://github.com/advisories/GHSA-px9f-whj3-246m",
  "cwes": [
    "CWE-93"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-px9f-whj3-246m",
  "summary": "Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type",
  "severity": "medium",
  "cvss_score": null,
  "ecosystems": [
    "erlang"
  ],
  "references": [
    "https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-49756",
    "https://github.com/wojtekmach/req/commit/74506ff2c5addf74df85d79dc726e9b2e264a8ba",
    "https://cna.erlef.org/cves/CVE-2026-49756.html",
    "https://github.com/wojtekmach/req/releases/tag/v0.6.0"
  ],
  "updated_at": "2026-07-29T15:29:15.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-29T15:29:14.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "req",
      "ecosystem": "erlang",
      "first_patched": "0.6.0",
      "vulnerable_range": ">= 0.5.3, < 0.6.0"
    }
  ]
}
04MEDIUM: Penelope unsafe tar extraction allows arbitrary local file write via crafted session archivemedium severity · penelope-shell-handler · CVE-2026-50558{"cve":"CVE-2026-50558","url":"https://github.com/advisories/GHSA-f42x-p2mx-hm8r…
EVENT. cms6aasbID. cms6aasbialhrkh0c3eay8909SRC. key:cmpxakb6
{
  "cve": "CVE-2026-50558",
  "url": "https://github.com/advisories/GHSA-f42x-p2mx-hm8r",
  "cwes": [
    "CWE-22"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-f42x-p2mx-hm8r",
  "summary": "Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive",
  "severity": "medium",
  "cvss_score": 5.9,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/brightio/penelope/security/advisories/GHSA-f42x-p2mx-hm8r",
    "https://github.com/brightio/penelope/commit/a040afb5db32c7e80b5e8a2f9b2164cf911cfa62",
    "https://github.com/brightio/penelope/releases/tag/v0.20.0",
    "https://github.com/advisories/GHSA-f42x-p2mx-hm8r"
  ],
  "updated_at": "2026-07-29T15:34:16.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L",
  "published_at": "2026-07-29T15:34:16.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "penelope-shell-handler",
      "ecosystem": "pip",
      "first_patched": "0.20.0",
      "vulnerable_range": "< 0.20.0"
    }
  ]
}
05LOW: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gatelow severity · @dynatrace-oss/dynatrace-mcp-server{"cve":null,"url":"https://github.com/advisories/GHSA-pc2w-4mq8-32qw","cwes":["C…
EVENT. cms6aarrID. cms6aarr9alhpkh0cpui6p2kwSRC. key:cmpxakb6
{
  "cve": null,
  "url": "https://github.com/advisories/GHSA-pc2w-4mq8-32qw",
  "cwes": [
    "CWE-862"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-pc2w-4mq8-32qw",
  "summary": "@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate",
  "severity": "low",
  "cvss_score": 3.7,
  "ecosystems": [
    "npm"
  ],
  "references": [
    "https://github.com/dynatrace-oss/dynatrace-mcp/security/advisories/GHSA-pc2w-4mq8-32qw",
    "https://github.com/dynatrace-oss/dynatrace-mcp/pull/529",
    "https://github.com/dynatrace-oss/dynatrace-mcp/commit/2851d3ce29d834c93b67f0db903c10e0b488e7ac",
    "https://github.com/dynatrace-oss/dynatrace-mcp/releases/tag/v1.8.7",
    "https://github.com/advisories/GHSA-pc2w-4mq8-32qw"
  ],
  "updated_at": "2026-07-29T15:36:20.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "published_at": "2026-07-29T15:36:19.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "@dynatrace-oss/dynatrace-mcp-server",
      "ecosystem": "npm",
      "first_patched": "1.8.7",
      "vulnerable_range": "< 1.8.7"
    }
  ]
}
06HIGH: Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilitieshigh severity · io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http · CVE-2026-50559{"cve":"CVE-2026-50559","url":"https://github.com/advisories/GHSA-qcxp-gm7m-4j5v…
EVENT. cms6aar6ID. cms6aar6talhlkh0chzsci61cSRC. key:cmpxakb6
{
  "cve": "CVE-2026-50559",
  "url": "https://github.com/advisories/GHSA-qcxp-gm7m-4j5v",
  "cwes": [
    "CWE-41",
    "CWE-178",
    "CWE-287",
    "CWE-551",
    "CWE-863"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-qcxp-gm7m-4j5v",
  "summary": "Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities",
  "severity": "high",
  "cvss_score": 7.5,
  "ecosystems": [
    "maven"
  ],
  "references": [
    "https://github.com/quarkusio/quarkus/security/advisories/GHSA-qcxp-gm7m-4j5v",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-50559",
    "https://github.com/quarkusio/quarkus/commit/919b80017d85564143a845b38e9cca54aff5b3cc",
    "https://access.redhat.com/errata/RHSA-2026:26017",
    "https://access.redhat.com/errata/RHSA-2026:26018"
  ],
  "updated_at": "2026-07-29T15:40:06.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "published_at": "2026-07-29T15:40:05.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "io.quarkus:quarkus-vertx-http",
      "ecosystem": "maven",
      "first_patched": "3.20.6.2",
      "vulnerable_range": "< 3.20.6.2"
    },
    {
      "name": "io.quarkus:quarkus-vertx-http",
      "ecosystem": "maven",
      "first_patched": "3.27.4.1",
      "vulnerable_range": ">= 3.21.0.CR1, < 3.27.4.1"
    },
    {
      "name": "io.quarkus:quarkus-vertx-http",
      "ecosystem": "maven",
      "first_patched": "3.33.2.1",
      "vulnerable_range": ">= 3.28.0.CR1, < 3.33.2.1"
    },
    {
      "name": "io.quarkus:quarkus-vertx-http",
      "ecosystem": "maven",
      "first_patched": "3.36.3",
      "vulnerable_range": ">= 3.34.0.CR1, < 3.36.3"
    },
    {
      "name": "io.quarkus:quarkus-vertx-http",
      "ecosystem": "maven",
      "first_patched": "3.37.0",
      "vulnerable_range": ">= 3.37.0.CR1, < 3.37.0"
    }
  ]
}
07CRITICAL: prebid-server's request forgery vulnerability allows for possible host environment data extractioncritical severity · github.com/prebid/prebid-server/v4, github.com/prebid/prebid-server/v3, github.com/prebid/prebid-server/v2 · CVE-2026-54735{"cve":"CVE-2026-54735","url":"https://github.com/advisories/GHSA-4p3g-4hcj-wpvx…
EVENT. cms6aaqmID. cms6aaqmqalhjkh0cr0r1beeoSRC. key:cmpxakb6
{
  "cve": "CVE-2026-54735",
  "url": "https://github.com/advisories/GHSA-4p3g-4hcj-wpvx",
  "cwes": [
    "CWE-918"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-4p3g-4hcj-wpvx",
  "summary": "prebid-server's request forgery vulnerability allows for possible host environment data extraction",
  "severity": "critical",
  "cvss_score": 10,
  "ecosystems": [
    "go"
  ],
  "references": [
    "https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx",
    "https://github.com/prebid/prebid-server/pull/4802",
    "https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3",
    "https://github.com/prebid/prebid-server/releases/tag/v4.4.0",
    "https://github.com/advisories/GHSA-4p3g-4hcj-wpvx"
  ],
  "updated_at": "2026-07-29T16:00:36.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
  "published_at": "2026-07-29T16:00:36.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "github.com/prebid/prebid-server/v4",
      "ecosystem": "go",
      "first_patched": "4.4.0",
      "vulnerable_range": "< 4.4.0"
    },
    {
      "name": "github.com/prebid/prebid-server/v3",
      "ecosystem": "go",
      "first_patched": null,
      "vulnerable_range": "<= 3.30.0"
    },
    {
      "name": "github.com/prebid/prebid-server/v2",
      "ecosystem": "go",
      "first_patched": null,
      "vulnerable_range": "<= 2.32.0"
    },
    {
      "name": "github.com/prebid/prebid-server",
      "ecosystem": "go",
      "first_patched": null,
      "vulnerable_range": "<= 0.275.0"
    }
  ]
}
08HIGH: AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escapinghigh severity · @aws/agentcore, @aws/agentcore, @aws/agentcore · CVE-2026-11393{"cve":"CVE-2026-11393","url":"https://github.com/advisories/GHSA-m4x6-gwgp-4pm7…
EVENT. cms6aaq1ID. cms6aaq1oalhhkh0cldi7lxwdSRC. key:cmpxakb6
{
  "cve": "CVE-2026-11393",
  "url": "https://github.com/advisories/GHSA-m4x6-gwgp-4pm7",
  "cwes": [
    "CWE-94"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-m4x6-gwgp-4pm7",
  "summary": "AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping",
  "severity": "high",
  "cvss_score": 9,
  "ecosystems": [
    "npm"
  ],
  "references": [
    "https://github.com/aws/agentcore-cli/security/advisories/GHSA-m4x6-gwgp-4pm7",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-11393",
    "https://github.com/aws/agentcore-cli/pull/1329",
    "https://github.com/aws/agentcore-cli/commit/ae1b932ec91bacdbb7a3521f9f1fc24479a3d504",
    "https://aws.amazon.com/security/security-bulletins/2026-040-aws"
  ],
  "updated_at": "2026-07-29T16:10:49.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
  "published_at": "2026-07-29T16:10:46.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "@aws/agentcore",
      "ecosystem": "npm",
      "first_patched": "0.14.2",
      "vulnerable_range": ">= 0.4.0, < 0.14.2"
    },
    {
      "name": "@aws/agentcore",
      "ecosystem": "npm",
      "first_patched": null,
      "vulnerable_range": ">= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0"
    },
    {
      "name": "@aws/agentcore",
      "ecosystem": "npm",
      "first_patched": "1.0.0-preview.9",
      "vulnerable_range": ">= 1.0.0-preview.1, < 1.0.0-preview.9"
    }
  ]
}
09MEDIUM: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193medium severity · matrix-commander{"cve":null,"url":"https://github.com/advisories/GHSA-wchh-9x6h-7f6p","cwes":["C…
EVENT. cms6aapgID. cms6aapgoalhfkh0ccjbktc2hSRC. key:cmpxakb6
{
  "cve": null,
  "url": "https://github.com/advisories/GHSA-wchh-9x6h-7f6p",
  "cwes": [
    "CWE-1395"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-wchh-9x6h-7f6p",
  "summary": "olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193",
  "severity": "medium",
  "cvss_score": null,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/8go/matrix-commander/security/advisories/GHSA-wchh-9x6h-7f6p",
    "https://github.com/8go/matrix-commander/issues/204#issuecomment-3523986979",
    "https://github.com/matrix-nio/matrix-nio/pull/555",
    "https://github.com/matrix-nio/matrix-nio/commit/71a1c808bc2ae6ea2a6e8effa7c11bd09796c626",
    "https://github.com/advisories/GHSA-wchh-9x6h-7f6p"
  ],
  "updated_at": "2026-07-29T16:11:49.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-29T16:11:45.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "matrix-commander",
      "ecosystem": "pip",
      "first_patched": null,
      "vulnerable_range": "<= 8.0.6"
    }
  ]
}
10HIGH: swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`high severity · swagger-typescript-api · CVE-2026-54660{"cve":"CVE-2026-54660","url":"https://github.com/advisories/GHSA-h754-fxp7-88wx…
EVENT. cms684hjID. cms684hj6akxjkh0ce28arw6lSRC. key:cmpxakb6
{
  "cve": "CVE-2026-54660",
  "url": "https://github.com/advisories/GHSA-h754-fxp7-88wx",
  "cwes": [
    "CWE-200",
    "CWE-201",
    "CWE-522",
    "CWE-918"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-h754-fxp7-88wx",
  "summary": "swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`",
  "severity": "high",
  "cvss_score": 7.4,
  "ecosystems": [
    "npm"
  ],
  "references": [
    "https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-h754-fxp7-88wx",
    "https://github.com/acacode/swagger-typescript-api/pull/1779",
    "https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
    "https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
    "https://github.com/advisories/GHSA-h754-fxp7-88wx"
  ],
  "updated_at": "2026-07-29T14:22:46.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
  "published_at": "2026-07-29T14:22:46.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "swagger-typescript-api",
      "ecosystem": "npm",
      "first_patched": "13.12.2",
      "vulnerable_range": "<= 13.12.1"
    }
  ]
}
showing 1–10 of 1,946older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/github-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above