GHSA-rmgv-gcwh-2pqh (CVE-2026-63656) published on repo but missing from global Advisory DB / MITRE / NVD / OSV
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Start by comparing the repository advisory API response with the global advisory endpoint for GHSA-rmgv-gcwh-2pqh, then check the MITRE, NVD, and OSV endpoints named in the report. Done means the published advisory is present globally and CVE-2026-63656 is available in the downstream records.
Written by the indexing model from the issue text.
Description
Summary
The repository security advisory GHSA-rmgv-gcwh-2pqh (flyimg/flyimg, CVE-2026-63656) was published on 2026-07-30 and the fix shipped in flyimg 1.12.3, but ~3 weeks later the advisory has not been promoted into the global GitHub Advisory Database and the CVE record has not propagated to MITRE, NVD, or OSV.
Advisory
- Repo advisory: https://github.com/flyimg/flyimg/security/advisories/GHSA-rmgv-gcwh-2pqh
- GHSA:
GHSA-rmgv-gcwh-2pqh - CVE:
CVE-2026-63656 - Affected:
flyimg/flyimg(Composer)0.1.2 <= 1.12.2— patched in1.12.3
What I observe (checked 2026-08-20)
gh api repos/flyimg/flyimg/security-advisories/GHSA-rmgv-gcwh-2pqh→state: published,published_at: 2026-07-30T08:19:16Z,cve_id: CVE-2026-63656, patched1.12.3.GET https://api.github.com/advisories/GHSA-rmgv-gcwh-2pqh→ 404 Not Found (not in the global Advisory Database).- MITRE
https://cveawg.mitre.org/api/cve/CVE-2026-63656→ 404CVE_RECORD_DNE(no record at all, not even RESERVED). - NVD API (
cveId=CVE-2026-63656) → 0 results. - OSV.dev (by CVE id and by GHSA id) → 404.
Ask
Please promote this published repo advisory into the global GitHub Advisory Database and push the CVE-2026-63656 record to MITRE so it propagates onward to NVD / OSV / Dependabot. Reporter credited on the advisory: @0xRenSec.
Thanks!
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 18h
- Merged PRs (30d)
- 48
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#9255 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
All issues in github/advisory-database
Similar issues
-
channels:add check:passed
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
confluentinc/dbt-confluent#160 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
AstrBotDevs/AstrBot#10205 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100