Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

32,405 advisories

Loading
golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement Critical
CVE-2026-46595 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status Critical
CVE-2026-42508 was published for golang.org/x/crypto/ssh/knownhosts (Go) Jun 25, 2026
golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes Critical
CVE-2026-39834 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed Critical
CVE-2026-39831 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS High
CVE-2026-39829 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh: Invoking memory leak when rejecting channels can lead to DoS Moderate
CVE-2026-39827 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh is vulnerable to invoking server panic during CheckHostKey/Authenticate flow Moderate
CVE-2026-39835 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh vulnerable to invoking bypass of certificate restrictions Moderate
CVE-2026-39828 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic High
CVE-2026-46597 was published for golang.org/x/crypto/ssh (Go) Jun 25, 2026
golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys Critical
CVE-2026-39832 was published for golang.org/x/crypto/ssh/agent (Go) Jun 25, 2026
golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints Critical
CVE-2026-39833 was published for golang.org/x/crypto/ssh/agent (Go) Jun 25, 2026
golang.org/x/crypto/ssh/agent: Invoking pathological inputs can lead to client panic Moderate
CVE-2026-46598 was published for golang.org/x/crypto/ssh/agent (Go) Jun 25, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise Critical
CVE-2026-55166 was published for lemur (pip) Jun 25, 2026
im-rootkid Credited to im-rootkid
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO Moderate
CVE-2026-55165 was published for lemur (pip) Jun 25, 2026
im-rootkid Credited to im-rootkid
Lemur user-update path stores plaintext passwords Moderate
CVE-2026-55164 was published for lemur (pip) Jun 25, 2026
sour-exploit Credited to sour-exploit
sour-exploit Credited to sour-exploit
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF Moderate
CVE-2026-55162 was published for lemur (pip) Jun 25, 2026
sour-exploit Credited to sour-exploit
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop High
CVE-2026-53461 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
vibhum-dubey Credited to vibhum-dubey
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition High
CVE-2026-53460 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
OwenSanzas Credited to OwenSanzas
ImageMagick: Policy Bypass can read disallowed files via symlink Moderate
CVE-2026-49219 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
GameZoneHacker Credited to GameZoneHacker
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions High
CVE-2026-49218 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
OwenSanzas Credited to OwenSanzas
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems Moderate
CVE-2026-48994 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
oduoke567 Credited to oduoke567
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder Moderate
CVE-2026-48734 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
omkhar Credited to omkhar
ImageMagick has an Infinite Loop in subimage-search with crafted image Moderate
CVE-2026-48733 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
omkhar Credited to omkhar
ProTip! Advisories are also available from the GraphQL API