GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,744
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,552 advisories
Filter by severity
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
High
CVE-2026-88008
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik entrypoint header-name sanitization bypassed via request trailers
High
CVE-2026-88004
was published
for
github.com/traefik/traefik/v3
(Go)
Sep 10, 2026
Traefik HTTP/3 Backend NTLM Connection Reuse
Critical
CVE-2026-88007
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
High
CVE-2026-88009
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
Moderate
CVE-2026-88014
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: http backend forwards custom/auth headers to a different host on redirect
Low
CVE-2026-88013
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Moderate
CVE-2026-88016
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone local: crafted Range request against a translated symlink panics (DoS)
Moderate
CVE-2026-88015
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
Critical
CVE-2026-88018
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: RC per-server auth-proxy bypass
Critical
CVE-2026-88044
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: FTP cross-session auth-proxy backend confusion
High
CVE-2026-88017
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: source object names can escape the configured root on upload
Moderate
CVE-2026-88046
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: S3 multipart declared-length memory exhaustion
High
CVE-2026-88045
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
High
CVE-2026-87011
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Moderate
CVE-2026-87012
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Moderate
CVE-2026-87013
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
Moderate
CVE-2026-87014
was published
for
open-webui
(pip)
Sep 10, 2026
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
High
CVE-2026-59965
was published
for
@jhb.software/payload-alt-text-plugin
(npm)
Sep 10, 2026
@argos-ci/core: CI Branch Name OS Command Injection
High
CVE-2026-59960
was published
for
@argos-ci/core
(npm)
Sep 10, 2026
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
High
GHSA-m3wp-48jr-vr4g
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
Moderate
CVE-2026-87015
was published
for
open-webui
(pip)
Sep 10, 2026
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
High
CVE-2026-87016
was published
for
open-webui
(pip)
Sep 10, 2026
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
Critical
CVE-2026-88062
was published
for
omniroute
(npm)
Sep 10, 2026
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Moderate
CVE-2026-86073
was published
for
n8n
(npm)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API