GitHub Advisories

topic · security/github-advisories
DOC.
security/github-advisories
REV.
1,982 evt
DATE.
03-JUN-2026
SCOPE.
custom
§01

about

Reviewed vulnerability advisories from the GitHub Advisory Database (npm, PyPI, Go, RubyGems, Maven, …) with severity, CVSS, and affected packages.

§02

recent events

LIVElast event 0s ago0 evt / 1h

showing 10 of 1,973 events in this window (1,982 total on topic). adjust the range or clear it with ALL.

range
iso 8601 utc
iso 8601 utc
01MEDIUM: MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize floodmedium severity · mcp · CVE-2026-67430{"cve":"CVE-2026-67430","url":"https://github.com/advisories/GHSA-52jp-gj8w-j6xh…
EVENT. cms7nn0rID. cms7nn0rwayn3kh0c1tluceu6SRC. key:cmpxakb6
{
  "cve": "CVE-2026-67430",
  "url": "https://github.com/advisories/GHSA-52jp-gj8w-j6xh",
  "cwes": [
    "CWE-401",
    "CWE-770"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-52jp-gj8w-j6xh",
  "summary": "MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood",
  "severity": "medium",
  "cvss_score": 5.3,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-52jp-gj8w-j6xh",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67430",
    "https://github.com/modelcontextprotocol/ruby-sdk/commit/afb968c468c178c4d3294b423fcce250621692f4",
    "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
    "https://github.com/advisories/GHSA-52jp-gj8w-j6xh"
  ],
  "updated_at": "2026-07-30T14:43:29.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "published_at": "2026-07-30T14:43:29.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "mcp",
      "ecosystem": "rubygems",
      "first_patched": "0.23.0",
      "vulnerable_range": "<= 0.22.0"
    }
  ]
}
02HIGH: MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransporthigh severity · mcp · CVE-2026-67432{"cve":"CVE-2026-67432","url":"https://github.com/advisories/GHSA-h669-8m4g-r2hc…
EVENT. cms7nn08ID. cms7nn08gayn1kh0cgfoa2n4xSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67432",
  "url": "https://github.com/advisories/GHSA-h669-8m4g-r2hc",
  "cwes": [
    "CWE-770"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-h669-8m4g-r2hc",
  "summary": "MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport",
  "severity": "high",
  "cvss_score": 7.5,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-h669-8m4g-r2hc",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67432",
    "https://github.com/modelcontextprotocol/ruby-sdk/commit/772e0cb1f9db69312006926eee59a7287ad50166",
    "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
    "https://github.com/advisories/GHSA-h669-8m4g-r2hc"
  ],
  "updated_at": "2026-07-30T14:44:08.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
  "published_at": "2026-07-30T14:44:06.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "mcp",
      "ecosystem": "rubygems",
      "first_patched": "0.23.0",
      "vulnerable_range": "<= 0.22.0"
    }
  ]
}
03HIGH: MCP Ruby SDK: Ruby SSE Session Poisoninghigh severity · mcp · CVE-2026-67431{"cve":"CVE-2026-67431","url":"https://github.com/advisories/GHSA-5p9g-j988-pcwv…
EVENT. cms7nmzoID. cms7nmzouaymzkh0cwotml2xxSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67431",
  "url": "https://github.com/advisories/GHSA-5p9g-j988-pcwv",
  "cwes": [
    "CWE-284"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-5p9g-j988-pcwv",
  "summary": "MCP Ruby SDK: Ruby SSE Session Poisoning",
  "severity": "high",
  "cvss_score": null,
  "ecosystems": [
    "rubygems"
  ],
  "references": [
    "https://github.com/modelcontextprotocol/ruby-sdk/security/advisories/GHSA-5p9g-j988-pcwv",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67431",
    "https://github.com/modelcontextprotocol/ruby-sdk/commit/35466605319a34e4c7808712ae9bb1ca1afb2356",
    "https://github.com/modelcontextprotocol/ruby-sdk/releases/tag/v0.23.0",
    "https://github.com/advisories/GHSA-5p9g-j988-pcwv"
  ],
  "updated_at": "2026-07-30T14:44:29.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T14:44:28.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "mcp",
      "ecosystem": "rubygems",
      "first_patched": "0.23.0",
      "vulnerable_range": "<= 0.22.0"
    }
  ]
}
04MEDIUM: linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirectmedium severity · linuxfabrik-lib · CVE-2026-67435{"cve":"CVE-2026-67435","url":"https://github.com/advisories/GHSA-4jc5-g844-4x33…
EVENT. cms7nmz4ID. cms7nmz4faymxkh0c7ub2q5mvSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67435",
  "url": "https://github.com/advisories/GHSA-4jc5-g844-4x33",
  "cwes": [
    "CWE-200",
    "CWE-918"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-4jc5-g844-4x33",
  "summary": "linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect",
  "severity": "medium",
  "cvss_score": null,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-4jc5-g844-4x33",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67435",
    "https://github.com/Linuxfabrik/lib/commit/6573ff9347e541200305d278d2663d2e54e052ff",
    "https://github.com/Linuxfabrik/lib/releases/tag/v6.0.0",
    "https://github.com/advisories/GHSA-4jc5-g844-4x33"
  ],
  "updated_at": "2026-07-30T14:46:13.000Z",
  "cvss_vector": null,
  "published_at": "2026-07-30T14:46:13.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "linuxfabrik-lib",
      "ecosystem": "pip",
      "first_patched": "6.0.0",
      "vulnerable_range": "< 6.0.0"
    }
  ]
}
05CRITICAL: Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)critical severity · flyto-core · CVE-2026-67429{"cve":"CVE-2026-67429","url":"https://github.com/advisories/GHSA-2956-977x-2w3r…
EVENT. cms7nmykID. cms7nmykraymtkh0cvjhgl01aSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67429",
  "url": "https://github.com/advisories/GHSA-2956-977x-2w3r",
  "cwes": [
    "CWE-22",
    "CWE-73"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-2956-977x-2w3r",
  "summary": "Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)",
  "severity": "critical",
  "cvss_score": 10,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/flytohub/flyto-core/security/advisories/GHSA-2956-977x-2w3r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67429",
    "https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
    "https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
    "https://github.com/advisories/GHSA-2956-977x-2w3r"
  ],
  "updated_at": "2026-07-30T14:46:44.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H",
  "published_at": "2026-07-30T14:46:43.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "flyto-core",
      "ecosystem": "pip",
      "first_patched": "2.26.7",
      "vulnerable_range": "< 2.26.7"
    }
  ]
}
06HIGH: Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedhigh severity · flyto-core · CVE-2026-67427{"cve":"CVE-2026-67427","url":"https://github.com/advisories/GHSA-hr7p-wg7r-hg9m…
EVENT. cms7nmy1ID. cms7nmy1paymrkh0ctek6hncpSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67427",
  "url": "https://github.com/advisories/GHSA-hr7p-wg7r-hg9m",
  "cwes": [
    "CWE-522",
    "CWE-668",
    "CWE-693"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-hr7p-wg7r-hg9m",
  "summary": "Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted",
  "severity": "high",
  "cvss_score": 8.6,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/flytohub/flyto-core/security/advisories/GHSA-hr7p-wg7r-hg9m",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67427",
    "https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
    "https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
    "https://github.com/advisories/GHSA-hr7p-wg7r-hg9m"
  ],
  "updated_at": "2026-07-30T14:47:03.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
  "published_at": "2026-07-30T14:47:01.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "flyto-core",
      "ecosystem": "pip",
      "first_patched": "2.26.7",
      "vulnerable_range": "< 2.26.7"
    }
  ]
}
07HIGH: Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlhigh severity · flyto-core · CVE-2026-67425{"cve":"CVE-2026-67425","url":"https://github.com/advisories/GHSA-qq9q-xgm3-xv9g…
EVENT. cms7nmxjID. cms7nmxjdaympkh0cuddm6i5qSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67425",
  "url": "https://github.com/advisories/GHSA-qq9q-xgm3-xv9g",
  "cwes": [
    "CWE-201",
    "CWE-522"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-qq9q-xgm3-xv9g",
  "summary": "Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url",
  "severity": "high",
  "cvss_score": 8.6,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/flytohub/flyto-core/security/advisories/GHSA-qq9q-xgm3-xv9g",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67425",
    "https://github.com/flytohub/flyto-core/commit/d5f89d71303e3c1e6418d347c5c55fcd173cc8cc",
    "https://github.com/flytohub/flyto-core/releases/tag/v2.26.6",
    "https://github.com/advisories/GHSA-qq9q-xgm3-xv9g"
  ],
  "updated_at": "2026-07-30T14:47:18.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
  "published_at": "2026-07-30T14:47:16.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "flyto-core",
      "ecosystem": "pip",
      "first_patched": "2.26.7",
      "vulnerable_range": "< 2.26.7"
    }
  ]
}
08CRITICAL: Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationcritical severity · flyto-core · CVE-2026-67426{"cve":"CVE-2026-67426","url":"https://github.com/advisories/GHSA-jx74-cqjv-2c67…
EVENT. cms7nmx1ID. cms7nmx15aymnkh0c9hm1jrilSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67426",
  "url": "https://github.com/advisories/GHSA-jx74-cqjv-2c67",
  "cwes": [
    "CWE-306",
    "CWE-522",
    "CWE-918"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-jx74-cqjv-2c67",
  "summary": "Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration",
  "severity": "critical",
  "cvss_score": 9.3,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/flytohub/flyto-core/security/advisories/GHSA-jx74-cqjv-2c67",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67426",
    "https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
    "https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
    "https://github.com/advisories/GHSA-jx74-cqjv-2c67"
  ],
  "updated_at": "2026-07-30T14:47:43.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
  "published_at": "2026-07-30T14:47:41.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "flyto-core",
      "ecosystem": "pip",
      "first_patched": "2.26.7",
      "vulnerable_range": "<= 2.26.6"
    }
  ]
}
09HIGH: Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)high severity · flyto-core · CVE-2026-67428{"cve":"CVE-2026-67428","url":"https://github.com/advisories/GHSA-pgwh-4jj4-qm8v…
EVENT. cms7nmwhID. cms7nmwhjaymlkh0ccab737vnSRC. key:cmpxakb6
{
  "cve": "CVE-2026-67428",
  "url": "https://github.com/advisories/GHSA-pgwh-4jj4-qm8v",
  "cwes": [
    "CWE-918"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-pgwh-4jj4-qm8v",
  "summary": "Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)",
  "severity": "high",
  "cvss_score": 8.5,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/flytohub/flyto-core/security/advisories/GHSA-pgwh-4jj4-qm8v",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67428",
    "https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
    "https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
    "https://github.com/advisories/GHSA-pgwh-4jj4-qm8v"
  ],
  "updated_at": "2026-07-30T14:48:09.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
  "published_at": "2026-07-30T14:48:05.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "flyto-core",
      "ecosystem": "pip",
      "first_patched": "2.26.7",
      "vulnerable_range": "<= 2.26.6"
    }
  ]
}
10HIGH: Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidationhigh severity · flyto-core · CVE-2026-67424{"cve":"CVE-2026-67424","url":"https://github.com/advisories/GHSA-c9hr-64h3-gxpc…
EVENT. cms7nmvqID. cms7nmvqxaymhkh0c8gs2ma72SRC. key:cmpxakb6
{
  "cve": "CVE-2026-67424",
  "url": "https://github.com/advisories/GHSA-c9hr-64h3-gxpc",
  "cwes": [
    "CWE-918"
  ],
  "source": "github_advisory_database",
  "ghsa_id": "GHSA-c9hr-64h3-gxpc",
  "summary": "Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation",
  "severity": "high",
  "cvss_score": 8.5,
  "ecosystems": [
    "pip"
  ],
  "references": [
    "https://github.com/flytohub/flyto-core/security/advisories/GHSA-c9hr-64h3-gxpc",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-67424",
    "https://github.com/flytohub/flyto-core/commit/0a0a528520ec18f5a21f1ddf858a71cc1edfb6e9",
    "https://github.com/flytohub/flyto-core/releases/tag/v2.26.7",
    "https://github.com/advisories/GHSA-c9hr-64h3-gxpc"
  ],
  "updated_at": "2026-07-30T14:48:19.000Z",
  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
  "published_at": "2026-07-30T14:48:16.000Z",
  "withdrawn_at": null,
  "affected_packages": [
    {
      "name": "flyto-core",
      "ecosystem": "pip",
      "first_patched": "2.26.7",
      "vulnerable_range": "<= 2.26.6"
    }
  ]
}
showing 1–10 of 1,973older →
§03

subscribe

three pathways carry every event on this topic. pick the one that fits your agent.

GETrss feed
any reader · no auth
https://api.callsign.sh/v1/public/channels/security/topics/github-advisories/feed.xml
GETjson pull
poll on your schedule · optional since/until
https://api.callsign.sh/v1/public/channels/security/topics/github-advisories.json
POSTwebhook
push delivery · one POST per event
log in to subscribe →
subscribe by reader, by pull loop, or by webhook above