GitHub Advisories
topic · security/github-advisories
§01
about
Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.
§02
recent events
LIVElast event 0s ago0 evt / 1h
showing 10 of 1,973 events in this window (1,982 total on topic). adjust the range or clear it with ALL.
range
01MEDIUM: MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodmedium severity · mcp · CVE-2026-67430{"cve":"CVE-2026-67430","url":"https://github.com/advisories/GHSA-52jp-gj8w-j6xh…
EVENT. cms7nn0rID. cms7nn0rwayn3kh0c1tluceu6SRC. key:cmpxakb6…
{
"cve": "CVE-2026-67430",
"url": "https://github.com/advisories/GHSA-52jp-gj8w-j6xh",
"cwes": [
"CWE-401",
"CWE-770"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-52jp-gj8w-j6xh",
"summary": "MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood",
"severity": "medium",
"cvss_score": 5.3,
"ecosystems": [
"rubygems"
],
"references": [
"https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-52jp-gj8w-j6xh",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67430",
"https://github.com/modelcontextprotocol/ruby-sdk/commit/afb968c468c178c4d3294b423fcce250621692f4",
"https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
"https://github.com/advisories/GHSA-52jp-gj8w-j6xh"
],
"updated_at": "2026-07-30T14:43:29.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"published_at": "2026-07-30T14:43:29.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "mcp",
"ecosystem": "rubygems",
"first_patched": "0.23.0",
"vulnerable_range": "<= 0.22.0"
}
]
}02HIGH: MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransporthigh severity · mcp · CVE-2026-67432{"cve":"CVE-2026-67432","url":"https://github.com/advisories/GHSA-h669-8m4g-r2hc…
EVENT. cms7nn08ID. cms7nn08gayn1kh0cgfoa2n4xSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67432",
"url": "https://github.com/advisories/GHSA-h669-8m4g-r2hc",
"cwes": [
"CWE-770"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-h669-8m4g-r2hc",
"summary": "MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport",
"severity": "high",
"cvss_score": 7.5,
"ecosystems": [
"rubygems"
],
"references": [
"https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-h669-8m4g-r2hc",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67432",
"https://github.com/modelcontextprotocol/ruby-sdk/commit/772e0cb1f9db69312006926eee59a7287ad50166",
"https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
"https://github.com/advisories/GHSA-h669-8m4g-r2hc"
],
"updated_at": "2026-07-30T14:44:08.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"published_at": "2026-07-30T14:44:06.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "mcp",
"ecosystem": "rubygems",
"first_patched": "0.23.0",
"vulnerable_range": "<= 0.22.0"
}
]
}03HIGH: MCP Ruby SDK: Ruby SSE Session Poisoninghigh severity · mcp · CVE-2026-67431{"cve":"CVE-2026-67431","url":"https://github.com/advisories/GHSA-5p9g-j988-pcwv…
EVENT. cms7nmzoID. cms7nmzouaymzkh0cwotml2xxSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67431",
"url": "https://github.com/advisories/GHSA-5p9g-j988-pcwv",
"cwes": [
"CWE-284"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-5p9g-j988-pcwv",
"summary": "MCP Ruby SDK: Ruby SSE Session Poisoning",
"severity": "high",
"cvss_score": null,
"ecosystems": [
"rubygems"
],
"references": [
"https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-5p9g-j988-pcwv",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67431",
"https://github.com/modelcontextprotocol/ruby-sdk/commit/35466605319a34e4c7808712ae9bb1ca1afb2356",
"https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
"https://github.com/advisories/GHSA-5p9g-j988-pcwv"
],
"updated_at": "2026-07-30T14:44:29.000Z",
"cvss_vector": null,
"published_at": "2026-07-30T14:44:28.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "mcp",
"ecosystem": "rubygems",
"first_patched": "0.23.0",
"vulnerable_range": "<= 0.22.0"
}
]
}04MEDIUM: linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirectmedium severity · linuxfabrik-lib · CVE-2026-67435{"cve":"CVE-2026-67435","url":"https://github.com/advisories/GHSA-4jc5-g844-4x33…
EVENT. cms7nmz4ID. cms7nmz4faymxkh0c7ub2q5mvSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67435",
"url": "https://github.com/advisories/GHSA-4jc5-g844-4x33",
"cwes": [
"CWE-200",
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-4jc5-g844-4x33",
"summary": "linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect",
"severity": "medium",
"cvss_score": null,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-4jc5-g844-4x33",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67435",
"https://github.com/Linuxfabrik/lib/commit/6573ff9347e541200305d278d2663d2e54e052ff",
"https://github.com/Linuxfabrik/lib/releases/tag/v6.0.0",
"https://github.com/advisories/GHSA-4jc5-g844-4x33"
],
"updated_at": "2026-07-30T14:46:13.000Z",
"cvss_vector": null,
"published_at": "2026-07-30T14:46:13.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "linuxfabrik-lib",
"ecosystem": "pip",
"first_patched": "6.0.0",
"vulnerable_range": "< 6.0.0"
}
]
}05CRITICAL: Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)critical severity · flyto-core · CVE-2026-67429{"cve":"CVE-2026-67429","url":"https://github.com/advisories/GHSA-2956-977x-2w3r…
EVENT. cms7nmykID. cms7nmykraymtkh0cvjhgl01aSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67429",
"url": "https://github.com/advisories/GHSA-2956-977x-2w3r",
"cwes": [
"CWE-22",
"CWE-73"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-2956-977x-2w3r",
"summary": "Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)",
"severity": "critical",
"cvss_score": 10,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67429",
"https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
"https://github.com/advisories/GHSA-2956-977x-2w3r"
],
"updated_at": "2026-07-30T14:46:44.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H",
"published_at": "2026-07-30T14:46:43.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "< 2.26.7"
}
]
}06HIGH: Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedhigh severity · flyto-core · CVE-2026-67427{"cve":"CVE-2026-67427","url":"https://github.com/advisories/GHSA-hr7p-wg7r-hg9m…
EVENT. cms7nmy1ID. cms7nmy1paymrkh0ctek6hncpSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67427",
"url": "https://github.com/advisories/GHSA-hr7p-wg7r-hg9m",
"cwes": [
"CWE-522",
"CWE-668",
"CWE-693"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-hr7p-wg7r-hg9m",
"summary": "Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted",
"severity": "high",
"cvss_score": 8.6,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-hr7p-wg7r-hg9m",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67427",
"https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
"https://github.com/advisories/GHSA-hr7p-wg7r-hg9m"
],
"updated_at": "2026-07-30T14:47:03.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"published_at": "2026-07-30T14:47:01.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "< 2.26.7"
}
]
}07HIGH: Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlhigh severity · flyto-core · CVE-2026-67425{"cve":"CVE-2026-67425","url":"https://github.com/advisories/GHSA-qq9q-xgm3-xv9g…
EVENT. cms7nmxjID. cms7nmxjdaympkh0cuddm6i5qSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67425",
"url": "https://github.com/advisories/GHSA-qq9q-xgm3-xv9g",
"cwes": [
"CWE-201",
"CWE-522"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-qq9q-xgm3-xv9g",
"summary": "Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url",
"severity": "high",
"cvss_score": 8.6,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-qq9q-xgm3-xv9g",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67425",
"https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
"https://github.com/advisories/GHSA-qq9q-xgm3-xv9g"
],
"updated_at": "2026-07-30T14:47:18.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"published_at": "2026-07-30T14:47:16.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "< 2.26.7"
}
]
}08CRITICAL: Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationcritical severity · flyto-core · CVE-2026-67426{"cve":"CVE-2026-67426","url":"https://github.com/advisories/GHSA-jx74-cqjv-2c67…
EVENT. cms7nmx1ID. cms7nmx15aymnkh0c9hm1jrilSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67426",
"url": "https://github.com/advisories/GHSA-jx74-cqjv-2c67",
"cwes": [
"CWE-306",
"CWE-522",
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-jx74-cqjv-2c67",
"summary": "Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration",
"severity": "critical",
"cvss_score": 9.3,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-jx74-cqjv-2c67",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67426",
"https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
"https://github.com/advisories/GHSA-jx74-cqjv-2c67"
],
"updated_at": "2026-07-30T14:47:43.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
"published_at": "2026-07-30T14:47:41.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "<= 2.26.6"
}
]
}09HIGH: Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)high severity · flyto-core · CVE-2026-67428{"cve":"CVE-2026-67428","url":"https://github.com/advisories/GHSA-pgwh-4jj4-qm8v…
EVENT. cms7nmwhID. cms7nmwhjaymlkh0ccab737vnSRC. key:cmpxakb6…
{
"cve": "CVE-2026-67428",
"url": "https://github.com/advisories/GHSA-pgwh-4jj4-qm8v",
"cwes": [
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-pgwh-4jj4-qm8v",
"summary": "Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)",
"severity": "high",
"cvss_score": 8.5,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-pgwh-4jj4-qm8v",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67428",
"https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
"https://github.com/advisories/GHSA-pgwh-4jj4-qm8v"
],
"updated_at": "2026-07-30T14:48:09.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"published_at": "2026-07-30T14:48:05.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "<= 2.26.6"
}
]
}10HIGH: Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationhigh severity · flyto-core · CVE-2026-67424{"cve":"CVE-2026-67424","url":"https://github.com/advisories/GHSA-c9hr-64h3-gxpc…
EVENT. cms7nmvqID. cms7nmvqxaymhkh0c8gs2ma72SRC. key:cmpxakb6…
{
"cve": "CVE-2026-67424",
"url": "https://github.com/advisories/GHSA-c9hr-64h3-gxpc",
"cwes": [
"CWE-918"
],
"source": "github_advisory_database",
"ghsa_id": "GHSA-c9hr-64h3-gxpc",
"summary": "Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation",
"severity": "high",
"cvss_score": 8.5,
"ecosystems": [
"pip"
],
"references": [
"https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc",
"https://nvd.nist.gov/vuln/detail/CVE-2026-67424",
"https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
"https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
"https://github.com/advisories/GHSA-c9hr-64h3-gxpc"
],
"updated_at": "2026-07-30T14:48:19.000Z",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"published_at": "2026-07-30T14:48:16.000Z",
"withdrawn_at": null,
"affected_packages": [
{
"name": "flyto-core",
"ecosystem": "pip",
"first_patched": "2.26.7",
"vulnerable_range": "<= 2.26.6"
}
]
}showing 1–10 of 1,973older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/github-advisories.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above