GitHub Advisories
topic · security/github-advisories
§01
about
Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 1,946 events in this window (1,982 total on topic). adjust the range or clear it with ALL.
range
01MEDIUM: veraPDF Parser DoS via PostScript Type 1 Font Programsmedium severity · org.verapdf:parser, org.verapdf:parser · CVE-2026-54081{"cve":"CVE-2026-54081","url":"https://github.com/advisories/GHSA-7c26-995w-6f47…
EVENT. cms6aau1ID. cms6aau1aalhzkh0cb0zqueqzSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54081",
"url": "https://github.com/advisories/GHSA-7c26-995w-6f47",
"cwes": [
"CWE-1325"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-7c26-995w-6f47",
"summary": "veraPDF Parser DoS via PostScript Type 1 Font Programs",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-7c26-995w-6f47",
"https://github.com/veraPDF/veraPDF-parser/pull/703",
"https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce",
"https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4",
"https://github.com/advisories/GHSA-7c26-995w-6f47"
],
"updated_at": "2026-07-29T15:19:06.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T15:19:04.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "org.verapdf:parser",
"ecosystem": "maven",
"first_patched": "1.30.2",
"vulnerable_range": "<= 1.30.1"
},
{
"name": "org.verapdf:parser",
"ecosystem": "maven",
"first_patched": "1.31.23",
"vulnerable_range": ">= 1.31.1, <= 1.31.22"
}
]
}02HIGH: Req vulnerable to unbounded archive/compression extraction triggered by response content-typehigh severity · req · CVE-2026-49755{"cve":"CVE-2026-49755","url":"https://github.com/advisories/GHSA-655f-mp8p-96gv…
EVENT. cms6aathID. cms6aath2alhxkh0cly8hj59xSRC. key:cmpxakb6…
{
"cve": "CVE-2026-49755",
"url": "https://github.com/advisories/GHSA-655f-mp8p-96gv",
"cwes": [
"CWE-409"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-655f-mp8p-96gv",
"summary": "Req vulnerable to unbounded archive/compression extraction triggered by response content-type",
"severity": "high",
"cvss_score": null,
"ecosystems": [
"erlang"
],
"references": [
"https://github.com/wojtekmach/req/security/advisories/GHSA-655f-mp8p-96gv",
"https://nvd.nist.gov/vuln/detail/CVE-2026-49755",
"https://github.com/wojtekmach/req/commit/84977e5b1a83f26e749d55ad06e3625464af4e8d",
"https://cna.erlef.org/cves/CVE-2026-49755.html",
"https://osv.dev/vulnerability/EEF-CVE-2026-49755"
],
"updated_at": "2026-07-29T15:23:18.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T15:23:16.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "req",
"ecosystem": "erlang",
"first_patched": "0.6.1",
"vulnerable_range": ">= 0.1.0, < 0.6.1"
}
]
}03MEDIUM: Req vulnerable to multipart form-data header injection via unescaped name/filename/content_typemedium severity · req · CVE-2026-49756{"cve":"CVE-2026-49756","url":"https://github.com/advisories/GHSA-px9f-whj3-246m…
EVENT. cms6aaswID. cms6aaswdalhtkh0cybjpvpeiSRC. key:cmpxakb6…
{
"cve": "CVE-2026-49756",
"url": "https://github.com/advisories/GHSA-px9f-whj3-246m",
"cwes": [
"CWE-93"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-px9f-whj3-246m",
"summary": "Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"erlang"
],
"references": [
"https://github.com/wojtekmach/req/security/advisories/GHSA-px9f-whj3-246m",
"https://nvd.nist.gov/vuln/detail/CVE-2026-49756",
"https://github.com/wojtekmach/req/commit/74506ff2c5addf74df85d79dc726e9b2e264a8ba",
"https://cna.erlef.org/cves/CVE-2026-49756.html",
"https://github.com/wojtekmach/req/releases/tag/v0.6.0"
],
"updated_at": "2026-07-29T15:29:15.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T15:29:14.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "req",
"ecosystem": "erlang",
"first_patched": "0.6.0",
"vulnerable_range": ">= 0.5.3, < 0.6.0"
}
]
}04MEDIUM: Penelope unsafe tar extraction allows arbitrary local file write via crafted session archivemedium severity · penelope-shell-handler · CVE-2026-50558{"cve":"CVE-2026-50558","url":"https://github.com/advisories/GHSA-f42x-p2mx-hm8r…
EVENT. cms6aasbID. cms6aasbialhrkh0c3eay8909SRC. key:cmpxakb6…
{
"cve": "CVE-2026-50558",
"url": "https://github.com/advisories/GHSA-f42x-p2mx-hm8r",
"cwes": [
"CWE-22"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-f42x-p2mx-hm8r",
"summary": "Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive",
"severity": "medium",
"cvss_score": 5.9,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/brightio/penelope/security/advisories/GHSA-f42x-p2mx-hm8r",
"https://github.com/brightio/penelope/commit/a040afb5db32c7e80b5e8a2f9b2164cf911cfa62",
"https://github.com/brightio/penelope/releases/tag/v0.20.0",
"https://github.com/advisories/GHSA-f42x-p2mx-hm8r"
],
"updated_at": "2026-07-29T15:34:16.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L",
"published_at": "2026-07-29T15:34:16.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "penelope-shell-handler",
"ecosystem": "pip",
"first_patched": "0.20.0",
"vulnerable_range": "< 0.20.0"
}
]
}05LOW: @dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gatelow severity · @dynatrace-oss/dynatrace-mcp-server{"cve":null,"url":"https://github.com/advisories/GHSA-pc2w-4mq8-32qw","cwes":["C…
EVENT. cms6aarrID. cms6aarr9alhpkh0cpui6p2kwSRC. key:cmpxakb6…
{
"cve": null,
"url": "https://github.com/advisories/GHSA-pc2w-4mq8-32qw",
"cwes": [
"CWE-862"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-pc2w-4mq8-32qw",
"summary": "@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate",
"severity": "low",
"cvss_score": 3.7,
"ecosystems": [
"npm"
],
"references": [
"https://github.com/dynatrace-oss/dynatrace-mcp/security/advisories/GHSA-pc2w-4mq8-32qw",
"https://github.com/dynatrace-oss/dynatrace-mcp/pull/529",
"https://github.com/dynatrace-oss/dynatrace-mcp/commit/2851d3ce29d834c93b67f0db903c10e0b488e7ac",
"https://github.com/dynatrace-oss/dynatrace-mcp/releases/tag/v1.8.7",
"https://github.com/advisories/GHSA-pc2w-4mq8-32qw"
],
"updated_at": "2026-07-29T15:36:20.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"published_at": "2026-07-29T15:36:19.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "@dynatrace-oss/dynatrace-mcp-server",
"ecosystem": "npm",
"first_patched": "1.8.7",
"vulnerable_range": "< 1.8.7"
}
]
}06HIGH: Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilitieshigh severity · io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http · CVE-2026-50559{"cve":"CVE-2026-50559","url":"https://github.com/advisories/GHSA-qcxp-gm7m-4j5v…
EVENT. cms6aar6ID. cms6aar6talhlkh0chzsci61cSRC. key:cmpxakb6…
{
"cve": "CVE-2026-50559",
"url": "https://github.com/advisories/GHSA-qcxp-gm7m-4j5v",
"cwes": [
"CWE-41",
"CWE-178",
"CWE-287",
"CWE-551",
"CWE-863"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-qcxp-gm7m-4j5v",
"summary": "Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities",
"severity": "high",
"cvss_score": 7.5,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/quarkusio/quarkus/security/advisories/GHSA-qcxp-gm7m-4j5v",
"https://nvd.nist.gov/vuln/detail/CVE-2026-50559",
"https://github.com/quarkusio/quarkus/commit/919b80017d85564143a845b38e9cca54aff5b3cc",
"https://access.redhat.com/errata/RHSA-2026:26017",
"https://access.redhat.com/errata/RHSA-2026:26018"
],
"updated_at": "2026-07-29T15:40:06.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"published_at": "2026-07-29T15:40:05.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "io.quarkus:quarkus-vertx-http",
"ecosystem": "maven",
"first_patched": "3.20.6.2",
"vulnerable_range": "< 3.20.6.2"
},
{
"name": "io.quarkus:quarkus-vertx-http",
"ecosystem": "maven",
"first_patched": "3.27.4.1",
"vulnerable_range": ">= 3.21.0.CR1, < 3.27.4.1"
},
{
"name": "io.quarkus:quarkus-vertx-http",
"ecosystem": "maven",
"first_patched": "3.33.2.1",
"vulnerable_range": ">= 3.28.0.CR1, < 3.33.2.1"
},
{
"name": "io.quarkus:quarkus-vertx-http",
"ecosystem": "maven",
"first_patched": "3.36.3",
"vulnerable_range": ">= 3.34.0.CR1, < 3.36.3"
},
{
"name": "io.quarkus:quarkus-vertx-http",
"ecosystem": "maven",
"first_patched": "3.37.0",
"vulnerable_range": ">= 3.37.0.CR1, < 3.37.0"
}
]
}07CRITICAL: prebid-server's request forgery vulnerability allows for possible host environment data extractioncritical severity · github.com/prebid/prebid-server/v4, github.com/prebid/prebid-server/v3, github.com/prebid/prebid-server/v2 · CVE-2026-54735{"cve":"CVE-2026-54735","url":"https://github.com/advisories/GHSA-4p3g-4hcj-wpvx…
EVENT. cms6aaqmID. cms6aaqmqalhjkh0cr0r1beeoSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54735",
"url": "https://github.com/advisories/GHSA-4p3g-4hcj-wpvx",
"cwes": [
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-4p3g-4hcj-wpvx",
"summary": "prebid-server's request forgery vulnerability allows for possible host environment data extraction",
"severity": "critical",
"cvss_score": 10,
"ecosystems": [
"go"
],
"references": [
"https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx",
"https://github.com/prebid/prebid-server/pull/4802",
"https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3",
"https://github.com/prebid/prebid-server/releases/tag/v4.4.0",
"https://github.com/advisories/GHSA-4p3g-4hcj-wpvx"
],
"updated_at": "2026-07-29T16:00:36.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"published_at": "2026-07-29T16:00:36.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "github.com/prebid/prebid-server/v4",
"ecosystem": "go",
"first_patched": "4.4.0",
"vulnerable_range": "< 4.4.0"
},
{
"name": "github.com/prebid/prebid-server/v3",
"ecosystem": "go",
"first_patched": null,
"vulnerable_range": "<= 3.30.0"
},
{
"name": "github.com/prebid/prebid-server/v2",
"ecosystem": "go",
"first_patched": null,
"vulnerable_range": "<= 2.32.0"
},
{
"name": "github.com/prebid/prebid-server",
"ecosystem": "go",
"first_patched": null,
"vulnerable_range": "<= 0.275.0"
}
]
}08HIGH: AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escapinghigh severity · @aws/agentcore, @aws/agentcore, @aws/agentcore · CVE-2026-11393{"cve":"CVE-2026-11393","url":"https://github.com/advisories/GHSA-m4x6-gwgp-4pm7…
EVENT. cms6aaq1ID. cms6aaq1oalhhkh0cldi7lxwdSRC. key:cmpxakb6…
{
"cve": "CVE-2026-11393",
"url": "https://github.com/advisories/GHSA-m4x6-gwgp-4pm7",
"cwes": [
"CWE-94"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-m4x6-gwgp-4pm7",
"summary": "AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping",
"severity": "high",
"cvss_score": 9,
"ecosystems": [
"npm"
],
"references": [
"https://github.com/aws/agentcore-cli/security/advisories/GHSA-m4x6-gwgp-4pm7",
"https://nvd.nist.gov/vuln/detail/CVE-2026-11393",
"https://github.com/aws/agentcore-cli/pull/1329",
"https://github.com/aws/agentcore-cli/commit/ae1b932ec91bacdbb7a3521f9f1fc24479a3d504",
"https://aws.amazon.com/security/security-bulletins/2026-040-aws"
],
"updated_at": "2026-07-29T16:10:49.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"published_at": "2026-07-29T16:10:46.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "@aws/agentcore",
"ecosystem": "npm",
"first_patched": "0.14.2",
"vulnerable_range": ">= 0.4.0, < 0.14.2"
},
{
"name": "@aws/agentcore",
"ecosystem": "npm",
"first_patched": null,
"vulnerable_range": ">= 0.3.0-preview.7.0, <= 0.3.0-preview.9.0"
},
{
"name": "@aws/agentcore",
"ecosystem": "npm",
"first_patched": "1.0.0-preview.9",
"vulnerable_range": ">= 1.0.0-preview.1, < 1.0.0-preview.9"
}
]
}09MEDIUM: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193medium severity · matrix-commander{"cve":null,"url":"https://github.com/advisories/GHSA-wchh-9x6h-7f6p","cwes":["C…
EVENT. cms6aapgID. cms6aapgoalhfkh0ccjbktc2hSRC. key:cmpxakb6…
{
"cve": null,
"url": "https://github.com/advisories/GHSA-wchh-9x6h-7f6p",
"cwes": [
"CWE-1395"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-wchh-9x6h-7f6p",
"summary": "olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/8go/matrix-commander/security/advisories/GHSA-wchh-9x6h-7f6p",
"https://github.com/8go/matrix-commander/issues/204#issuecomment-3523986979",
"https://github.com/matrix-nio/matrix-nio/pull/555",
"https://github.com/matrix-nio/matrix-nio/commit/71a1c808bc2ae6ea2a6e8effa7c11bd09796c626",
"https://github.com/advisories/GHSA-wchh-9x6h-7f6p"
],
"updated_at": "2026-07-29T16:11:49.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T16:11:45.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "matrix-commander",
"ecosystem": "pip",
"first_patched": null,
"vulnerable_range": "<= 8.0.6"
}
]
}10HIGH: swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`high severity · swagger-typescript-api · CVE-2026-54660{"cve":"CVE-2026-54660","url":"https://github.com/advisories/GHSA-h754-fxp7-88wx…
EVENT. cms684hjID. cms684hj6akxjkh0ce28arw6lSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54660",
"url": "https://github.com/advisories/GHSA-h754-fxp7-88wx",
"cwes": [
"CWE-200",
"CWE-201",
"CWE-522",
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-h754-fxp7-88wx",
"summary": "swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`",
"severity": "high",
"cvss_score": 7.4,
"ecosystems": [
"npm"
],
"references": [
"https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-h754-fxp7-88wx",
"https://github.com/acacode/swagger-typescript-api/pull/1779",
"https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de",
"https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2",
"https://github.com/advisories/GHSA-h754-fxp7-88wx"
],
"updated_at": "2026-07-29T14:22:46.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
"published_at": "2026-07-29T14:22:46.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "swagger-typescript-api",
"ecosystem": "npm",
"first_patched": "13.12.2",
"vulnerable_range": "<= 13.12.1"
}
]
}showing 1–10 of 1,946older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above