GitHub Advisories
topic · security/github-advisories
§01
about
Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 1,964 events in this window (1,982 total on topic). adjust the range or clear it with ALL.
range
01HIGH: Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationhigh severity · flyto-core · CVE-2026-67424{"cve":"CVE-2026-67424","url":"https://github.com/advisories/GHSA-c9hr-64h3-gxpc…
EVENT. cms7nmvqID. cms7nmvqxaymhkh0c8gs2ma72SRC. key:cmpxakb6…
{
"cve": "CVE-2026-67424",
"url": "https://github.com/advisories/GHSA-c9hr-64h3-gxpc",
"cwes": [
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-c9hr-64h3-gxpc",
"summary": "Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation",
"severity": "high",
"cvss_score": 8.5,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67424",
"https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
"https://github.com/advisories/GHSA-c9hr-64h3-gxpc"
],
"updated_at": "2026-07-30T14:48:19.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"published_at": "2026-07-30T14:48:16.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "<= 2.26.6"
}
]
}02MEDIUM: OpenTelemetry Javaagent RMI context propagation allows resource exhaustionmedium severity · io.opentelemetry.javaagent:opentelemetry-javaagent · CVE-2026-54712{"cve":"CVE-2026-54712","url":"https://github.com/advisories/GHSA-fq3f-m5qm-99f5…
EVENT. cms6em8wID. cms6em8w2amldkh0crahd37diSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54712",
"url": "https://github.com/advisories/GHSA-fq3f-m5qm-99f5",
"cwes": [
"CWE-400"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-fq3f-m5qm-99f5",
"summary": "OpenTelemetry Javaagent RMI context propagation allows resource exhaustion",
"severity": "medium",
"cvss_score": 5.3,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-fq3f-m5qm-99f5",
"https://nvd.nist.gov/vuln/detail/CVE-2026-54712",
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/17870",
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/6ef18806d5daa4913619e4cb33d2d7ed6a853c22",
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases/tag/v2.27.0"
],
"updated_at": "2026-07-29T17:16:33.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"published_at": "2026-07-29T17:16:32.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "io.opentelemetry.javaagent:opentelemetry-javaagent",
"ecosystem": "maven",
"first_patched": "2.27.0",
"vulnerable_range": "< 2.27.0"
}
]
}03MEDIUM: OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwordsmedium severity · io.opentelemetry.javaagent:opentelemetry-javaagent · CVE-2026-54704{"cve":"CVE-2026-54704","url":"https://github.com/advisories/GHSA-rwqx-fvqh-6wm4…
EVENT. cms6em86ID. cms6em86haml7kh0cl1smwmbkSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54704",
"url": "https://github.com/advisories/GHSA-rwqx-fvqh-6wm4",
"cwes": [
"CWE-532"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-rwqx-fvqh-6wm4",
"summary": "OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords",
"severity": "medium",
"cvss_score": 6.5,
"ecosystems": [
"maven"
],
"references": [
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-rwqx-fvqh-6wm4",
"https://nvd.nist.gov/vuln/detail/CVE-2026-54704",
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18754",
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/7ac7fa6fda6c2e3b65bc5d3c6eba050311a49511",
"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases/tag/v2.28.0"
],
"updated_at": "2026-07-29T17:18:34.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"published_at": "2026-07-29T17:18:34.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "io.opentelemetry.javaagent:opentelemetry-javaagent",
"ecosystem": "maven",
"first_patched": "2.28.0-alpha",
"vulnerable_range": "< 2.28.0-alpha"
}
]
}04MEDIUM: mathlive's Lack of Escaping of HTML allows for XSSmedium severity · mathlive · CVE-2026-54705{"cve":"CVE-2026-54705","url":"https://github.com/advisories/GHSA-fm7p-gw32-828p…
EVENT. cms6em7dID. cms6em7doaml5kh0c1o1d24meSRC. key:cmpxakb6…
{
"cve": "CVE-2026-54705",
"url": "https://github.com/advisories/GHSA-fm7p-gw32-828p",
"cwes": [
"CWE-116"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-fm7p-gw32-828p",
"summary": "mathlive's Lack of Escaping of HTML allows for XSS",
"severity": "medium",
"cvss_score": 6.3,
"ecosystems": [
"npm"
],
"references": [
"https://github.com/arnog/mathlive/security/advisories/GHSA-fm7p-gw32-828p",
"https://github.com/arnog/mathlive/issues/3028",
"https://github.com/arnog/mathlive/commit/5fe1c46153883f9ec0249a5c8c34e64aaae9cfb8",
"https://github.com/advisories/GHSA-fm7p-gw32-828p"
],
"updated_at": "2026-07-29T17:21:27.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"published_at": "2026-07-29T17:21:26.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "mathlive",
"ecosystem": "npm",
"first_patched": "0.110.0",
"vulnerable_range": "<= 0.109.2"
}
]
}05HIGH: Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposurehigh severity · alextselegidis/easyappointments · CVE-2026-55651{"cve":"CVE-2026-55651","url":"https://github.com/advisories/GHSA-4vmm-5qvc-w5p7…
EVENT. cms6cgpyID. cms6cgpynam25kh0c3ldy3zdeSRC. key:cmpxakb6…
{
"cve": "CVE-2026-55651",
"url": "https://github.com/advisories/GHSA-4vmm-5qvc-w5p7",
"cwes": [
"CWE-200"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-4vmm-5qvc-w5p7",
"summary": "Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure",
"severity": "high",
"cvss_score": 7.1,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-4vmm-5qvc-w5p7",
"https://nvd.nist.gov/vuln/detail/CVE-2026-55651",
"https://github.com/alextselegidis/easyappointments/commit/ebbe41130dafa58b0716426c56c8cfd4c22dbceb",
"https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0",
"https://github.com/advisories/GHSA-4vmm-5qvc-w5p7"
],
"updated_at": "2026-07-29T16:22:19.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
"published_at": "2026-07-29T16:22:17.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": null,
"vulnerable_range": "= 1.5.2"
}
]
}06LOW: Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal networklow severity · alextselegidis/easyappointments · CVE-2026-52840{"cve":"CVE-2026-52840","url":"https://github.com/advisories/GHSA-pm5p-7w5h-jm5q…
EVENT. cms6cgpeID. cms6cgpepam23kh0cz4c6dz04SRC. key:cmpxakb6…
{
"cve": "CVE-2026-52840",
"url": "https://github.com/advisories/GHSA-pm5p-7w5h-jm5q",
"cwes": [
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-pm5p-7w5h-jm5q",
"summary": "Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network",
"severity": "low",
"cvss_score": 2.7,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-pm5p-7w5h-jm5q",
"https://nvd.nist.gov/vuln/detail/CVE-2026-52840",
"https://github.com/alextselegidis/easyappointments/commit/2da2baed18ec32ad7916e507815709c8f010d510",
"https://github.com/alextselegidis/easyappointments/commit/4abb10545d83ac1a57d03f6502376ee67696ea7c",
"https://github.com/alextselegidis/easyappointments/commit/6b34b78c47790dfd1dec27cf62926db51be276e9"
],
"updated_at": "2026-07-29T16:24:30.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
"published_at": "2026-07-29T16:24:27.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": null,
"vulnerable_range": "<= 1.5.2"
}
]
}07LOW: Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypasslow severity · alextselegidis/easyappointments · CVE-2026-52839{"cve":"CVE-2026-52839","url":"https://github.com/advisories/GHSA-w8xc-8g92-v77h…
EVENT. cms6cgouID. cms6cgoucam21kh0cnlfsl4ucSRC. key:cmpxakb6…
{
"cve": "CVE-2026-52839",
"url": "https://github.com/advisories/GHSA-w8xc-8g92-v77h",
"cwes": [
"CWE-639",
"CWE-862"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-w8xc-8g92-v77h",
"summary": "Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass",
"severity": "low",
"cvss_score": 3.3,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-w8xc-8g92-v77h",
"https://nvd.nist.gov/vuln/detail/CVE-2026-52839",
"https://github.com/alextselegidis/easyappointments/commit/725eafa647308846ce887657db12771a829e42ef",
"https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0",
"https://github.com/advisories/GHSA-w8xc-8g92-v77h"
],
"updated_at": "2026-07-29T16:26:27.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N",
"published_at": "2026-07-29T16:26:25.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": "1.6.0",
"vulnerable_range": "<= 1.5.2"
}
]
}08MEDIUM: Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule pagemedium severity · alextselegidis/easyappointments · CVE-2026-52837{"cve":"CVE-2026-52837","url":"https://github.com/advisories/GHSA-xgr6-pqjv-3pf8…
EVENT. cms6cgoaID. cms6cgoa0am1zkh0cf0xogmcwSRC. key:cmpxakb6…
{
"cve": "CVE-2026-52837",
"url": "https://github.com/advisories/GHSA-xgr6-pqjv-3pf8",
"cwes": [
"CWE-200",
"CWE-639"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-xgr6-pqjv-3pf8",
"summary": "Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-xgr6-pqjv-3pf8",
"https://nvd.nist.gov/vuln/detail/CVE-2026-52837",
"https://github.com/alextselegidis/easyappointments/commit/40bb0b31b531540bc9006efce4220eb0a437ed2b",
"https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0",
"https://github.com/advisories/GHSA-xgr6-pqjv-3pf8"
],
"updated_at": "2026-07-29T16:28:25.000Z",
"cvss_vector": null,
"published_at": "2026-07-29T16:28:23.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": null,
"vulnerable_range": "<= 1.5.2"
}
]
}09LOW: Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google synclow severity · alextselegidis/easyappointments · CVE-2026-52841{"cve":"CVE-2026-52841","url":"https://github.com/advisories/GHSA-8hm4-r66f-29wr…
EVENT. cms6cgnpID. cms6cgnpnam1xkh0ccvda9zheSRC. key:cmpxakb6…
{
"cve": "CVE-2026-52841",
"url": "https://github.com/advisories/GHSA-8hm4-r66f-29wr",
"cwes": [
"CWE-639"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-8hm4-r66f-29wr",
"summary": "Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync",
"severity": "low",
"cvss_score": 3.1,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-8hm4-r66f-29wr",
"https://nvd.nist.gov/vuln/detail/CVE-2026-52841",
"https://github.com/alextselegidis/easyappointments/commit/4b2d245d2cd2058dc76e05f6eb65b26699268471",
"https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0",
"https://github.com/advisories/GHSA-8hm4-r66f-29wr"
],
"updated_at": "2026-07-29T16:29:27.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N",
"published_at": "2026-07-29T16:29:26.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": null,
"vulnerable_range": "<= 1.5.2"
}
]
}10LOW: Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSSlow severity · alextselegidis/easyappointments · CVE-2026-52838{"cve":"CVE-2026-52838","url":"https://github.com/advisories/GHSA-996f-334j-67g7…
EVENT. cms6cgn5ID. cms6cgn5bam1vkh0c5ljweeaxSRC. key:cmpxakb6…
{
"cve": "CVE-2026-52838",
"url": "https://github.com/advisories/GHSA-996f-334j-67g7",
"cwes": [
"CWE-79"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-996f-334j-67g7",
"summary": "Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS",
"severity": "low",
"cvss_score": 2.6,
"ecosystems": [
"composer"
],
"references": [
"https://github.com/alextselegidis/easyappointments/security/advisories/GHSA-996f-334j-67g7",
"https://nvd.nist.gov/vuln/detail/CVE-2026-52838",
"https://github.com/alextselegidis/easyappointments/commit/629a0415f54f75556c17f4f5d9c77fda1fdbdeae",
"https://github.com/alextselegidis/easyappointments/releases/tag/1.6.0",
"https://github.com/advisories/GHSA-996f-334j-67g7"
],
"updated_at": "2026-07-29T16:30:11.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N",
"published_at": "2026-07-29T16:30:09.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "alextselegidis/easyappointments",
"ecosystem": "composer",
"first_patched": null,
"vulnerable_range": "<= 1.5.2"
}
]
}showing 1–10 of 1,964older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above