-
Notifications
You must be signed in to change notification settings - Fork 530
Pull requests: github/advisory-database
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
[GHSA-ww7g-4gwx-m7wj] @nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
#6898
opened Feb 15, 2026 by
asrar-mared
Loading…
[GHSA-2c4m-g7rx-63q7] set-in Affected by Prototype Pollution
#6897
opened Feb 15, 2026 by
asrar-mared
Loading…
[GHSA-wvr6-395c-5pxr] CediPay Affected by Improper Input Validation in Payment Processing
#6896
opened Feb 15, 2026 by
asrar-mared
Loading…
[GHSA-x9vf-53q3-cvx6] CASL Ability is Vulnerable to Prototype Pollution
#6895
opened Feb 15, 2026 by
asrar-mared
Loading…
[GHSA-pxg6-pf52-xh8x] cookie accepts cookie name, path, and domain with out of bounds characters
#6891
opened Feb 15, 2026 by
asrar-mared
Loading…
[GHSA-4pg4-qvpc-4q3h] Multer vulnerable to Denial of Service from maliciously crafted requests
#6890
opened Feb 15, 2026 by
asrar-mared
Loading…
Integrate ZAYED‑SHIELD GHSA Remediation Engine into GHSA‑856v‑8qm2‑9wjv
#6889
opened Feb 15, 2026 by
asrar-mared
Loading…
Advisory Improvement: Enhancements and Cleanup for GHSA Workflow (6866)
#6888
opened Feb 15, 2026 by
asrar-mared
Loading…
Full Remediation Framework for Operator‑SDK Privilege Escalation Vulnerabilities
#6886
opened Feb 14, 2026 by
asrar-mared
Loading…
⭐ Introduce Automated Remediation Framework for Operator‑SDK Vulnerabilities
#6885
opened Feb 14, 2026 by
asrar-mared
Loading…
[GHSA-856v-8qm2-9wjv] operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
#6884
opened Feb 14, 2026 by
asrar-mared
Loading…
[GHSA-4hx9-48xh-5mxr] Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
#6883
opened Feb 14, 2026 by
eminaktas
Loading…
[GHSA-895x-rfqp-jh5c] Keycloak does not invalidate offline sessions when the offline_access scope is removed
#6882
opened Feb 14, 2026 by
eminaktas
Loading…
[GHSA-64w3-5q9m-68xf] Keycloak does not invalidate sessions when "Remember Me" is disabled
#6881
opened Feb 14, 2026 by
eminaktas
Loading…
[GHSA-6f65-4fv2-wwch] Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
#6880
opened Feb 14, 2026 by
ali963git
Loading…
[GHSA-2g4f-4pwh-qvx6] ajv (Another JSON Schema Validator) through version 8.17...
#6879
opened Feb 14, 2026 by
epoberezkin
Loading…
Previous Next
ProTip!
Find all pull requests that aren't related to any open issues with -linked:issue.