{"advisories":{"pheditor\/pheditor":[{"advisoryId":"PKSA-jw7m-7sxt-c8zt","packageName":"pheditor\/pheditor","remoteId":"GHSA-f25v-x6vr-962g","title":"Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password","link":"https:\/\/github.com\/advisories\/GHSA-f25v-x6vr-962g","cve":null,"affectedVersions":"\u003C2.0.8","source":"GitHub","reportedAt":"2026-07-24 21:54:24","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-f25v-x6vr-962g"}]},{"advisoryId":"PKSA-2169-f5hg-9g35","packageName":"pheditor\/pheditor","remoteId":"GHSA-g3hq-hphg-8fhh","title":"Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE \u2014 surviving vector after the metacharacter-sanitization fixes","link":"https:\/\/github.com\/advisories\/GHSA-g3hq-hphg-8fhh","cve":null,"affectedVersions":"\u003C=2.0.6","source":"GitHub","reportedAt":"2026-07-24 21:45:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g3hq-hphg-8fhh"}]}],"poweradmin\/poweradmin":[{"advisoryId":"PKSA-wfnt-jmc8-c3b3","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-h4hf-v6w5-897x","title":"Poweradmin: API user-update endpoint leads to a non-admin reset any user\u0027s password and take over the superuser account","link":"https:\/\/github.com\/advisories\/GHSA-h4hf-v6w5-897x","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4|\u003E=4.0.0,\u003C4.2.5","source":"GitHub","reportedAt":"2026-07-24 21:54:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h4hf-v6w5-897x"}]},{"advisoryId":"PKSA-ybnj-2pv1-jwh7","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-rm67-g9ch-vxff","title":"Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own","link":"https:\/\/github.com\/advisories\/GHSA-rm67-g9ch-vxff","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4|\u003E=4.0.0,\u003C4.2.5|\u003E=3.0.0,\u003C3.9.11","source":"GitHub","reportedAt":"2026-07-24 21:55:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rm67-g9ch-vxff"}]},{"advisoryId":"PKSA-zmp4-g5nd-b65p","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-cmwh-g2h8-c222","title":"Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover","link":"https:\/\/github.com\/advisories\/GHSA-cmwh-g2h8-c222","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4|\u003E=4.1.0,\u003C4.2.5","source":"GitHub","reportedAt":"2026-07-24 21:56:02","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cmwh-g2h8-c222"}]}],"phpoffice\/phpspreadsheet":[{"advisoryId":"PKSA-m9cr-9614-rsf7","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-2mrg-gjxq-2gvr","title":"PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion","link":"https:\/\/github.com\/advisories\/GHSA-2mrg-gjxq-2gvr","cve":"CVE-2026-59932","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 15:00:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mrg-gjxq-2gvr"}]},{"advisoryId":"PKSA-r22k-87hv-mfk4","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-xh5m-36r6-47m3","title":"PHPSpreadsheet: XLS\/OLE sector-chain self-loop causes memory exhaustion","link":"https:\/\/github.com\/advisories\/GHSA-xh5m-36r6-47m3","cve":"CVE-2026-59933","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 15:01:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xh5m-36r6-47m3"}]},{"advisoryId":"PKSA-dqzt-yst9-1w9y","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-6hq5-7373-42rg","title":"PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist","link":"https:\/\/github.com\/advisories\/GHSA-6hq5-7373-42rg","cve":"CVE-2026-59931","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 14:55:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6hq5-7373-42rg"}]}],"dompdf\/dompdf":[{"advisoryId":"PKSA-gh7h-hhy4-byg7","packageName":"dompdf\/dompdf","remoteId":"GHSA-8hg6-c449-896m","title":"Dompdf: Uncontrolled resource consumption based on declared BMP dimensions","link":"https:\/\/github.com\/advisories\/GHSA-8hg6-c449-896m","cve":"CVE-2026-59941","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:50:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hg6-c449-896m"}]},{"advisoryId":"PKSA-6r8f-nxsb-67bq","packageName":"dompdf\/dompdf","remoteId":"GHSA-f5gf-2cj8-52g2","title":"Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps","link":"https:\/\/github.com\/advisories\/GHSA-f5gf-2cj8-52g2","cve":"CVE-2026-59942","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:51:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f5gf-2cj8-52g2"}]},{"advisoryId":"PKSA-cv56-2228-pzr6","packageName":"dompdf\/dompdf","remoteId":"GHSA-j8qw-6jw8-r297","title":"Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem","link":"https:\/\/github.com\/advisories\/GHSA-j8qw-6jw8-r297","cve":"CVE-2026-59943","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:52:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j8qw-6jw8-r297"}]},{"advisoryId":"PKSA-mwt3-h9tv-kx78","packageName":"dompdf\/dompdf","remoteId":"GHSA-cx96-42px-69fm","title":"Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI","link":"https:\/\/github.com\/advisories\/GHSA-cx96-42px-69fm","cve":"CVE-2026-56722","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:30:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cx96-42px-69fm"}]},{"advisoryId":"PKSA-mckv-s5hg-868k","packageName":"dompdf\/dompdf","remoteId":"GHSA-wvh6-f5jh-8gw4","title":"Dompdf: Chroot Validation Bypass","link":"https:\/\/github.com\/advisories\/GHSA-wvh6-f5jh-8gw4","cve":"CVE-2026-55554","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:06:48","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wvh6-f5jh-8gw4"}]},{"advisoryId":"PKSA-hp6n-n4kz-21wk","packageName":"dompdf\/dompdf","remoteId":"GHSA-7x2p-4jvh-6384","title":"Dompdf: File existence oracle via font-face stylesheet declaration","link":"https:\/\/github.com\/advisories\/GHSA-7x2p-4jvh-6384","cve":"CVE-2026-55555","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:07:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7x2p-4jvh-6384"}]}],"guzzlehttp\/psr7":[{"advisoryId":"PKSA-vznr-tgp9-fd7d","packageName":"guzzlehttp\/psr7","remoteId":"GHSA-c2w2-prh8-qm98","title":"guzzlehttp\/psr7: Host Confusion via Weak URI Host Validation","link":"https:\/\/github.com\/advisories\/GHSA-c2w2-prh8-qm98","cve":"CVE-2026-59882","affectedVersions":"\u003C2.12.3","source":"GitHub","reportedAt":"2026-07-21 18:35:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c2w2-prh8-qm98"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":null,"affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":null,"affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":null,"affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-bcdd-5xc7-gwfb","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-g446-98w2-8p5w","title":"Guzzle: Cookie Disclosure and Injection via IP-Address Domains","link":"https:\/\/github.com\/advisories\/GHSA-g446-98w2-8p5w","cve":"CVE-2026-59883","affectedVersions":"\u003C7.12.3","source":"GitHub","reportedAt":"2026-07-20 22:00:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g446-98w2-8p5w"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":null,"affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]}],"composer\/composer":[{"advisoryId":"PKSA-4pm6-g63v-5rkr","packageName":"composer\/composer","remoteId":"GHSA-g6xq-892h-64w3","title":"Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)","link":"https:\/\/github.com\/advisories\/GHSA-g6xq-892h-64w3","cve":"CVE-2026-59947","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 21:55:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g6xq-892h-64w3"}]},{"advisoryId":"PKSA-q3ht-3g42-rg8f","packageName":"composer\/composer","remoteId":"GHSA-gjfg-22fp-rrxx","title":"Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files","link":"https:\/\/github.com\/advisories\/GHSA-gjfg-22fp-rrxx","cve":"CVE-2026-59946","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 21:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gjfg-22fp-rrxx"}]},{"advisoryId":"PKSA-zcdk-qnhk-hq2g","packageName":"composer\/composer","remoteId":"GHSA-499r-g7pc-vmp9","title":"Composer: Arbitrary file write outside vendor via malicious transitive package name","link":"https:\/\/github.com\/advisories\/GHSA-499r-g7pc-vmp9","cve":"CVE-2026-59948","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 19:15:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-499r-g7pc-vmp9"}]}]}}