Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

GHSA-rmgv-gcwh-2pqh (CVE-2026-63656) published on repo but missing from global Advisory DB / MITRE / NVD / OSV

Open
#9,171 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active

Research direction

Start by comparing the repository advisory API response with the global advisory endpoint for GHSA-rmgv-gcwh-2pqh, then check the MITRE, NVD, and OSV endpoints named in the report. Done means the published advisory is present globally and CVE-2026-63656 is available in the downstream records.

Written by the indexing model from the issue text.

Description

Summary

The repository security advisory GHSA-rmgv-gcwh-2pqh (flyimg/flyimg, CVE-2026-63656) was published on 2026-07-30 and the fix shipped in flyimg 1.12.3, but ~3 weeks later the advisory has not been promoted into the global GitHub Advisory Database and the CVE record has not propagated to MITRE, NVD, or OSV.

Advisory
What I observe (checked 2026-08-20)
  • gh api repos/flyimg/flyimg/security-advisories/GHSA-rmgv-gcwh-2pqhstate: published, published_at: 2026-07-30T08:19:16Z, cve_id: CVE-2026-63656, patched 1.12.3.
  • GET https://api.github.com/advisories/GHSA-rmgv-gcwh-2pqh404 Not Found (not in the global Advisory Database).
  • MITRE https://cveawg.mitre.org/api/cve/CVE-2026-63656404 CVE_RECORD_DNE (no record at all, not even RESERVED).
  • NVD API (cveId=CVE-2026-63656) → 0 results.
  • OSV.dev (by CVE id and by GHSA id) → 404.
Ask

Please promote this published repo advisory into the global GitHub Advisory Database and push the CVE-2026-63656 record to MITRE so it propagates onward to NVD / OSV / Dependabot. Reporter credited on the advisory: @0xRenSec.

Thanks!

Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 18h
Merged PRs (30d)
48

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Databases issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.