Summary
The repository security advisory GHSA-rmgv-gcwh-2pqh (flyimg/flyimg, CVE-2026-63656) was published on 2026-07-30 and the fix shipped in flyimg 1.12.3, but ~3 weeks later the advisory has not been promoted into the global GitHub Advisory Database and the CVE record has not propagated to MITRE, NVD, or OSV.
Advisory
- Repo advisory: GHSA-rmgv-gcwh-2pqh
- GHSA:
GHSA-rmgv-gcwh-2pqh
- CVE:
CVE-2026-63656
- Affected:
flyimg/flyimg (Composer) 0.1.2 <= 1.12.2 — patched in 1.12.3
What I observe (checked 2026-08-20)
gh api repos/flyimg/flyimg/security-advisories/GHSA-rmgv-gcwh-2pqh → state: published, published_at: 2026-07-30T08:19:16Z, cve_id: CVE-2026-63656, patched 1.12.3.
GET https://api.github.com/advisories/GHSA-rmgv-gcwh-2pqh → 404 Not Found (not in the global Advisory Database).
- MITRE
https://cveawg.mitre.org/api/cve/CVE-2026-63656 → 404 CVE_RECORD_DNE (no record at all, not even RESERVED).
- NVD API (
cveId=CVE-2026-63656) → 0 results.
- OSV.dev (by CVE id and by GHSA id) → 404.
Ask
Please promote this published repo advisory into the global GitHub Advisory Database and push the CVE-2026-63656 record to MITRE so it propagates onward to NVD / OSV / Dependabot. Reporter credited on the advisory: @0xRenSec.
Thanks!
Summary
The repository security advisory GHSA-rmgv-gcwh-2pqh (flyimg/flyimg, CVE-2026-63656) was published on 2026-07-30 and the fix shipped in flyimg 1.12.3, but ~3 weeks later the advisory has not been promoted into the global GitHub Advisory Database and the CVE record has not propagated to MITRE, NVD, or OSV.
Advisory
GHSA-rmgv-gcwh-2pqhCVE-2026-63656flyimg/flyimg(Composer)0.1.2 <= 1.12.2— patched in1.12.3What I observe (checked 2026-08-20)
gh api repos/flyimg/flyimg/security-advisories/GHSA-rmgv-gcwh-2pqh→state: published,published_at: 2026-07-30T08:19:16Z,cve_id: CVE-2026-63656, patched1.12.3.GET https://api.github.com/advisories/GHSA-rmgv-gcwh-2pqh→ 404 Not Found (not in the global Advisory Database).https://cveawg.mitre.org/api/cve/CVE-2026-63656→ 404CVE_RECORD_DNE(no record at all, not even RESERVED).cveId=CVE-2026-63656) → 0 results.Ask
Please promote this published repo advisory into the global GitHub Advisory Database and push the
CVE-2026-63656record to MITRE so it propagates onward to NVD / OSV / Dependabot. Reporter credited on the advisory: @0xRenSec.Thanks!