{"source":"github-security","name":"GitHub Security Advisories","kind":"widget","via":"aiden","records":[{"id":"GHSA-pr2v-jx2c-wg9f","title":"Tornado vulnerable to Header Injection and XSS via reason argument","subtitle":"2026-07-20T18:55:11Z","value":"medium","href":"https://api.github.com/advisories/GHSA-pr2v-jx2c-wg9f"},{"id":"GHSA-42h9-826w-cgv3","title":"Axios: Excessive recursion in formDataToJSON can cause denial of service","subtitle":"2026-07-20T17:58:59Z","value":"medium","href":"https://api.github.com/advisories/GHSA-42h9-826w-cgv3"},{"id":"GHSA-xj6q-8x83-jv6g","title":"Axios: Prototype pollution auth subfields can inject Basic auth","subtitle":"2026-07-20T17:51:17Z","value":"medium","href":"https://api.github.com/advisories/GHSA-xj6q-8x83-jv6g"},{"id":"GHSA-pmv8-rq9r-6j72","title":"Axios: Deep formToJSON Key Recursion Can Cause Denial of Service","subtitle":"2026-07-20T17:48:18Z","value":"medium","href":"https://api.github.com/advisories/GHSA-pmv8-rq9r-6j72"},{"id":"GHSA-8qqm-fp2q-v734","title":"Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies","subtitle":"2026-07-17T21:49:48Z","value":"high","href":"https://api.github.com/advisories/GHSA-8qqm-fp2q-v734"},{"id":"GHSA-5587-2x54-jj6h","title":"Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication","subtitle":"2026-07-17T21:46:18Z","value":"medium","href":"https://api.github.com/advisories/GHSA-5587-2x54-jj6h"},{"id":"GHSA-r95q-fp26-h3hc","title":"CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard","subtitle":"2026-07-17T21:35:10Z","value":"high","href":"https://api.github.com/advisories/GHSA-r95q-fp26-h3hc"},{"id":"GHSA-56r5-2p2f-7cxp","title":"PocketSphinx: Buffer overflows in language and acoustic model loading code","subtitle":"2026-07-17T21:19:17Z","value":"medium","href":"https://api.github.com/advisories/GHSA-56r5-2p2f-7cxp"},{"id":"GHSA-pgww-w46g-26qg","title":"AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass","subtitle":"2026-07-17T21:17:10Z","value":"medium","href":"https://api.github.com/advisories/GHSA-pgww-w46g-26qg"},{"id":"GHSA-mfr4-mq8w-vmg6","title":"PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs","subtitle":"2026-07-17T20:25:37Z","value":"medium","href":"https://api.github.com/advisories/GHSA-mfr4-mq8w-vmg6"},{"id":"GHSA-g77h-45rf-hcx4","title":"ExifReader HEIC/AVIF ISO-BMFF parser throws uncaught RangeError on truncated boxes","subtitle":"2026-07-17T20:19:39Z","value":"medium","href":"https://api.github.com/advisories/GHSA-g77h-45rf-hcx4"},{"id":"GHSA-937x-gpqr-72gg","title":"Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)","subtitle":"2026-07-17T20:11:35Z","value":"high","href":"https://api.github.com/advisories/GHSA-937x-gpqr-72gg"},{"id":"GHSA-c4gh-rv8h-q9vw","title":"Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader","subtitle":"2026-07-17T19:53:34Z","value":"high","href":"https://api.github.com/advisories/GHSA-c4gh-rv8h-q9vw"},{"id":"GHSA-wxhm-2mq7-7697","title":"Prompty: Arbitrary file read via file reference expansion","subtitle":"2026-07-17T19:46:05Z","value":"high","href":"https://api.github.com/advisories/GHSA-wxhm-2mq7-7697"},{"id":"GHSA-f7wf-v2vw-mpcx","title":"mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath","subtitle":"2026-07-17T19:23:07Z","value":"medium","href":"https://api.github.com/advisories/GHSA-f7wf-v2vw-mpcx"},{"id":"GHSA-cvpc-hccg-wmw4","title":"Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration","subtitle":"2026-07-17T19:05:57Z","value":"medium","href":"https://api.github.com/advisories/GHSA-cvpc-hccg-wmw4"},{"id":"GHSA-8qw8-rq86-9pc2","title":"Gitea has insufficient permission checks for Composer package source links","subtitle":"2026-07-17T19:04:37Z","value":"high","href":"https://api.github.com/advisories/GHSA-8qw8-rq86-9pc2"},{"id":"GHSA-vqrw-qphh-p34v","title":"TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard","subtitle":"2026-07-17T19:02:37Z","value":"medium","href":"https://api.github.com/advisories/GHSA-vqrw-qphh-p34v"},{"id":"GHSA-rjwr-m7qx-3fjr","title":"oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code","subtitle":"2026-07-17T18:50:17Z","value":"low","href":"https://api.github.com/advisories/GHSA-rjwr-m7qx-3fjr"},{"id":"GHSA-2v2f-mvfg-ph56","title":"meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token","subtitle":"2026-07-17T18:48:54Z","value":"high","href":"https://api.github.com/advisories/GHSA-2v2f-mvfg-ph56"},{"id":"GHSA-45gf-fjxp-cjpq","title":"meta-ads-mcp: Server-Side Request Forgery (SSRF) in `upload_ad_image` via Unrestricted `image_url` Fetch","subtitle":"2026-07-17T18:47:31Z","value":"high","href":"https://api.github.com/advisories/GHSA-45gf-fjxp-cjpq"},{"id":"GHSA-q38v-wp89-2w55","title":"sh _uid does not drop supplementary groups (incomplete privilege drop)","subtitle":"2026-07-17T18:41:38Z","value":"high","href":"https://api.github.com/advisories/GHSA-q38v-wp89-2w55"},{"id":"GHSA-mhww-p97m-3368","title":"AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance","subtitle":"2026-07-17T18:40:41Z","value":"high","href":"https://api.github.com/advisories/GHSA-mhww-p97m-3368"},{"id":"GHSA-8rqh-vxpr-x77p","title":"plone.restapi: Stored XSS by spoofing mime type","subtitle":"2026-07-17T18:36:34Z","value":"medium","href":"https://api.github.com/advisories/GHSA-8rqh-vxpr-x77p"},{"id":"GHSA-4r4f-gg25-rmg5","title":"plone.app.textfield: Stored XSS by spoofing mime type ","subtitle":"2026-07-17T18:35:57Z","value":"medium","href":"https://api.github.com/advisories/GHSA-4r4f-gg25-rmg5"},{"id":"GHSA-cwxq-rc9x-2jvv","title":"Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS","subtitle":"2026-07-17T18:14:08Z","value":"medium","href":"https://api.github.com/advisories/GHSA-cwxq-rc9x-2jvv"},{"id":"GHSA-v82g-2437-67m2","title":"vLLM: Speech-to-text upload size limit is enforced after full UploadFile read","subtitle":"2026-07-17T17:16:17Z","value":"medium","href":"https://api.github.com/advisories/GHSA-v82g-2437-67m2"},{"id":"GHSA-rwxx-mrjm-wc2m","title":"vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends","subtitle":"2026-07-17T17:10:37Z","value":"high","href":"https://api.github.com/advisories/GHSA-rwxx-mrjm-wc2m"},{"id":"GHSA-8wr5-jm2h-8r4f","title":"vLLM has Remote DoS via Invalid Recovered Token Reinjection","subtitle":"2026-07-17T17:08:03Z","value":"high","href":"https://api.github.com/advisories/GHSA-8wr5-jm2h-8r4f"},{"id":"GHSA-6c4r-fmh3-7rh8","title":"vLLM: Processing differential in multi-channel audio downmixing enables hidden-input/moderation bypass for audio models","subtitle":"2026-07-17T16:52:53Z","value":"medium","href":"https://api.github.com/advisories/GHSA-6c4r-fmh3-7rh8"}],"count":30,"generated_at":"2026-07-20T18:55:33.712Z"}