GitHub Advisories
topic · security/github-advisories
§01
about
Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 1,955 events in this window (1,982 total on topic). adjust the range or clear it with ALL.
range
01LOW: Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSSlow severity · alextselegidis/easyappointments · CVE-2026-52838{"cve":"CVE-2026-52838","url":"https://github.com/advisories/GHSA-996f-334j-67g7…
EVENT. cms6cgn5ID. cms6cgn5bam1vkh0c5ljweeaxSRC. key:cmpxakb6…
{
"cve": "CVE-2026-52838",
"url": "https://github.com/advisories/GHSA-996f-334j-67g7",
"cwes": [
"CWE-79"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-996f-334j-67g7",
"summary": "Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS",
"severity": "low",
"cvss_score": 2.6,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-996f-334j-67g7",
"https://nvd.nist.gov/vuln/detail/CVE-2026-52838",
"https://github.com/alextselegidis/easyappointments/commit/629a0415f54f75556c17f4f5d9c77fda1fdbdeae",
"https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0",
"https://github.com/advisories/GHSA-996f-334j-67g7"
],
"updated_at": "2026-07-29T16:30:11.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N",
"published_at": "2026-07-29T16:30:09.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": null,
"vulnerable_range": "<= 1.5.2"
}
]
}02HIGH: `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archivehigh severity · proot-distro · CVE-2026-54574{"cve":"CVE-2026-54574","url":"https://github.com/advisories/GHSA-9xq3-3fqg-4vg7…
EVENT. cms6cgmkID. cms6cgmktam1tkh0cb8pwdc8gSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54574",
"url": "https://github.com/advisories/GHSA-9xq3-3fqg-4vg7",
"cwes": [
"CWE-61"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-9xq3-3fqg-4vg7",
"summary": "`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive",
"severity": "high",
"cvss_score": 8.2,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/termux/proot-distro/security/advisories/GHSA-9xq3-3fqg-4vg7",
"https://github.com/termux/proot-distro/commit/a96d7a9667f38e45d812614852ee3915d1c0ae45",
"https://github.com/termux/proot-distro/releases/tag/v5.1.5",
"https://github.com/advisories/GHSA-9xq3-3fqg-4vg7"
],
"updated_at": "2026-07-29T16:32:35.000Z",
"cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
"published_at": "2026-07-29T16:32:34.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "proot-distro",
"ecosystem": "pip",
"first_patched": "5.1.5",
"vulnerable_range": "<= 5.1.4"
}
]
}03HIGH: proot-distro has a Container Isolation Bypass via Crafted Restore Archivehigh severity · proot-distro · CVE-2026-54727{"cve":"CVE-2026-54727","url":"https://github.com/advisories/GHSA-7h3g-4w2f-fj2f…
EVENT. cms6cgm0ID. cms6cgm0dam1rkh0ckwf86af5SRC. key:cmpxakb6…
{
"cve": "CVE-2026-54727",
"url": "https://github.com/advisories/GHSA-7h3g-4w2f-fj2f",
"cwes": [
"CWE-668"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-7h3g-4w2f-fj2f",
"summary": "proot-distro has a Container Isolation Bypass via Crafted Restore Archive",
"severity": "high",
"cvss_score": 8.2,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/termux/proot-distro/security/advisories/GHSA-7h3g-4w2f-fj2f",
"https://github.com/termux/proot-distro/commit/98aff324b7d8500ff75a8ca9ac087ee636be4716",
"https://github.com/termux/proot-distro/releases/tag/v5.1.6",
"https://github.com/advisories/GHSA-7h3g-4w2f-fj2f"
],
"updated_at": "2026-07-29T16:42:14.000Z",
"cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
"published_at": "2026-07-29T16:42:11.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "proot-distro",
"ecosystem": "pip",
"first_patched": "5.1.6",
"vulnerable_range": "<= 5.1.5"
}
]
}04HIGH: ZITADEL Users Can Self-Verify Email/Phone via APIhigh severity · github.com/zitadel/zitadel, github.com/zitadel/zitadel, github.com/zitadel/zitadel · CVE-2026-54693{"cve":"CVE-2026-54693","url":"https://github.com/advisories/GHSA-jq8w-8q2f-ffm9…
EVENT. cms6cglfID. cms6cglfham1pkh0cohjc1xcxSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54693",
"url": "https://github.com/advisories/GHSA-jq8w-8q2f-ffm9",
"cwes": [
"CWE-863"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-jq8w-8q2f-ffm9",
"summary": "ZITADEL Users Can Self-Verify Email/Phone via API",
"severity": "high",
"cvss_score": null,
"ecosystems": [
"go"
],
"references": [
"https://github.com/zitadel/zitadel/security/advisories/GHSA-jq8w-8q2f-ffm9",
"https://github.com/zitadel/zitadel/commit/90f310212d3a5075084a603bf61fed549c92956d",
"https://github.com/zitadel/zitadel/commit/a1748b2f0326ddf7be0de44b4f980ae2c07c0151",
"https://github.com/zitadel/zitadel/commit/ed09b3df7f43e870423e4d8f2757e6894481604f",
"https://github.com/zitadel/zitadel/releases/tag/v3.4.11"
],
"updated_at": "2026-07-29T16:54:53.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T16:54:49.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "github.com/zitadel/zitadel",
"ecosystem": "go",
"first_patched": null,
"vulnerable_range": ">= 4.0.0, < 4.15.1"
},
{
"name": "github.com/zitadel/zitadel",
"ecosystem": "go",
"first_patched": null,
"vulnerable_range": ">= 2.43.0, < 3.4.11"
},
{
"name": "github.com/zitadel/zitadel",
"ecosystem": "go",
"first_patched": "1.80.0-v2.20.0.20260608144108-ed09b3df7f43",
"vulnerable_range": "< 1.80.0-v2.20.0.20260608144108-ed09b3df7f43"
}
]
}05CRITICAL: Logging operator has Fluentd configuration injection that allows remote code executioncritical severity · github.com/kube-logging/logging-operator · CVE-2026-54680{"cve":"CVE-2026-54680","url":"https://github.com/advisories/GHSA-mjqf-28ph-426h…
EVENT. cms6cgkvID. cms6cgkv3am1nkh0cbpr5bf2zSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54680",
"url": "https://github.com/advisories/GHSA-mjqf-28ph-426h",
"cwes": [
"CWE-74",
"CWE-77"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-mjqf-28ph-426h",
"summary": "Logging operator has Fluentd configuration injection that allows remote code execution",
"severity": "critical",
"cvss_score": 9.9,
"ecosystems": [
"go"
],
"references": [
"https://github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426h",
"https://github.com/kube-logging/logging-operator/commit/cf437d7f1e056c78740bf5716ac8bdebcf002425",
"https://github.com/kube-logging/logging-operator/releases/tag/6.6.0",
"https://github.com/advisories/GHSA-mjqf-28ph-426h"
],
"updated_at": "2026-07-29T17:01:29.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"published_at": "2026-07-29T17:01:29.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "github.com/kube-logging/logging-operator",
"ecosystem": "go",
"first_patched": "0.0.0-20260608145523-cf437d7f1e05",
"vulnerable_range": "< 0.0.0-20260608145523-cf437d7f1e05"
}
]
}06HIGH: netfoil: Incorrect block responses could lead to localhost traffichigh severity · github.com/tinfoil-factory/netfoil{"cve":null,"url":"https://github.com/advisories/GHSA-xvg2-cgv6-6h7v","cwes":["C…
EVENT. cms6cgk8ID. cms6cgk8aam1jkh0cfw9ve712SRC. key:cmpxakb6…
{
"cve": null,
"url": "https://github.com/advisories/GHSA-xvg2-cgv6-6h7v",
"cwes": [
"CWE-693"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-xvg2-cgv6-6h7v",
"summary": "netfoil: Incorrect block responses could lead to localhost traffic",
"severity": "high",
"cvss_score": null,
"ecosystems": [
"go"
],
"references": [
"https://github.com/tinfoil-factory/netfoil/security/advisories/GHSA-xvg2-cgv6-6h7v",
"https://github.com/tinfoil-factory/netfoil/pull/33",
"https://github.com/tinfoil-factory/netfoil/commit/891d3513c77999a9deef9f23506807d9653ee448",
"https://github.com/tinfoil-factory/netfoil/releases/tag/v0.4.0",
"https://github.com/advisories/GHSA-xvg2-cgv6-6h7v"
],
"updated_at": "2026-07-29T17:03:48.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T17:03:48.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "github.com/tinfoil-factory/netfoil",
"ecosystem": "go",
"first_patched": "0.4.0",
"vulnerable_range": "< 0.4.0"
}
]
}07LOW: ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversallow severity · activerecord-tenanted{"cve":null,"url":"https://github.com/advisories/GHSA-pmwx-rm49-xv39","cwes":["C…
EVENT. cms6cgjoID. cms6cgjomam1hkh0cd3wes86uSRC. key:cmpxakb6…
{
"cve": null,
"url": "https://github.com/advisories/GHSA-pmwx-rm49-xv39",
"cwes": [
"CWE-22"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-pmwx-rm49-xv39",
"summary": "ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal",
"severity": "low",
"cvss_score": null,
"ecosystems": [
"rubygems"
],
"references": [
"https://github.com/basecamp/activerecord-tenanted/security/advisories/GHSA-pmwx-rm49-xv39",
"https://github.com/rails/rails/security/advisories/GHSA-9xrj-h377-fr87",
"https://github.com/basecamp/activerecord-tenanted/pull/307",
"https://github.com/basecamp/activerecord-tenanted/commit/b242c8ad9bf58bbd7f5a032d153b0f29db54b9ba",
"https://github.com/basecamp/activerecord-tenanted/releases/tag/v0.7.0"
],
"updated_at": "2026-07-29T17:06:01.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T17:06:00.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "activerecord-tenanted",
"ecosystem": "rubygems",
"first_patched": "0.7.0",
"vulnerable_range": "< 0.7.0"
}
]
}08MEDIUM: veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFsmedium severity · org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta · CVE-2026-54082{"cve":"CVE-2026-54082","url":"https://github.com/advisories/GHSA-cg9x-g3gm-h5h6…
EVENT. cms6aav5ID. cms6aav54ali3kh0csi45zpfvSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54082",
"url": "https://github.com/advisories/GHSA-cg9x-g3gm-h5h6",
"cwes": [
"CWE-611"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-cg9x-g3gm-h5h6",
"summary": "veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs",
"severity": "medium",
"cvss_score": 6.5,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/veraPDF/veraPDF-validation/security/advisories/GHSA-cg9x-g3gm-h5h6",
"https://github.com/veraPDF/veraPDF-validation/pull/730",
"https://github.com/veraPDF/veraPDF-validation/commit/94caa46c1a594512247fbd46c808edae39469542",
"https://github.com/veraPDF/veraPDF-validation/commit/cacd9436d0de40b0e58cc7d2dbb06451619e61ec",
"https://github.com/advisories/GHSA-cg9x-g3gm-h5h6"
],
"updated_at": "2026-07-29T15:14:32.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"published_at": "2026-07-29T15:14:32.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "org.verapdf:validation-model",
"ecosystem": "maven",
"first_patched": "1.30.2",
"vulnerable_range": ">= 1.17.35, <= 1.30.1"
},
{
"name": "org.verapdf:validation-model",
"ecosystem": "maven",
"first_patched": "1.31.71",
"vulnerable_range": ">= 1.31.1, <= 1.31.70"
},
{
"name": "org.verapdf:validation-model-jakarta",
"ecosystem": "maven",
"first_patched": "1.30.2",
"vulnerable_range": ">= 1.17.35, <= 1.30.1"
},
{
"name": "org.verapdf:validation-model-jakarta",
"ecosystem": "maven",
"first_patched": "1.31.71",
"vulnerable_range": ">= 1.31.1, <= 1.31.70"
}
]
}09MEDIUM: veraPDF Parser DoS via PostScript CMap Streamsmedium severity · org.verapdf:parser, org.verapdf:parser · CVE-2026-54080{"cve":"CVE-2026-54080","url":"https://github.com/advisories/GHSA-jrmc-qg6p-94fp…
EVENT. cms6aaulID. cms6aaul7ali1kh0cw3az0vfgSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54080",
"url": "https://github.com/advisories/GHSA-jrmc-qg6p-94fp",
"cwes": [
"CWE-1325"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-jrmc-qg6p-94fp",
"summary": "veraPDF Parser DoS via PostScript CMap Streams",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-jrmc-qg6p-94fp",
"https://github.com/veraPDF/veraPDF-parser/pull/703",
"https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce",
"https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4",
"https://github.com/advisories/GHSA-jrmc-qg6p-94fp"
],
"updated_at": "2026-07-29T15:17:33.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T15:17:32.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "org.verapdf:parser",
"ecosystem": "maven",
"first_patched": "1.30.2",
"vulnerable_range": "<= 1.30.1"
},
{
"name": "org.verapdf:parser",
"ecosystem": "maven",
"first_patched": "1.31.23",
"vulnerable_range": ">= 1.31.1, <= 1.31.22"
}
]
}10MEDIUM: veraPDF Parser DoS via PostScript Type 1 Font Programsmedium severity · org.verapdf:parser, org.verapdf:parser · CVE-2026-54081{"cve":"CVE-2026-54081","url":"https://github.com/advisories/GHSA-7c26-995w-6f47…
EVENT. cms6aau1ID. cms6aau1aalhzkh0cb0zqueqzSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54081",
"url": "https://github.com/advisories/GHSA-7c26-995w-6f47",
"cwes": [
"CWE-1325"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-7c26-995w-6f47",
"summary": "veraPDF Parser DoS via PostScript Type 1 Font Programs",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-7c26-995w-6f47",
"https://github.com/veraPDF/veraPDF-parser/pull/703",
"https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce",
"https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4",
"https://github.com/advisories/GHSA-7c26-995w-6f47"
],
"updated_at": "2026-07-29T15:19:06.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T15:19:04.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "org.verapdf:parser",
"ecosystem": "maven",
"first_patched": "1.30.2",
"vulnerable_range": "<= 1.30.1"
},
{
"name": "org.verapdf:parser",
"ecosystem": "maven",
"first_patched": "1.31.23",
"vulnerable_range": ">= 1.31.1, <= 1.31.22"
}
]
}showing 1–10 of 1,955older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above