GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
1,796 advisories
Filter by severity
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
High
CVE-2026-88009
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik entrypoint header-name sanitization bypassed via request trailers
High
CVE-2026-88004
was published
for
github.com/traefik/traefik/v3
(Go)
Sep 10, 2026
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
High
CVE-2026-88008
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
High
CVE-2026-56668
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
emp3r0r has an unauthenticated HTTP Polling DoS
High
CVE-2026-61554
was published
for
github.com/jm33-m0/emp3r0r/core
(Go)
Sep 15, 2026
Pocketbase: Unhandled panic in worker goroutines
High
CVE-2026-82410
was published
for
github.com/pocketbase/pocketbase
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
High
CVE-2026-77403
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
High
CVE-2026-77404
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
High
CVE-2026-77406
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
High
CVE-2026-77407
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
High
CVE-2026-77410
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
High
CVE-2026-77412
was published
for
github.com/rabbitmq/amqp091-go
(Go)
Sep 17, 2026
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
High
CVE-2026-86043
was published
for
github.com/zalando/skipper
(Go)
Sep 17, 2026
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
High
CVE-2026-85731
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
CoreDNS: Unauthenticated memory exhaustion in custom transports
High
CVE-2026-82399
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
High
CVE-2026-86003
was published
for
github.com/coredns/coredns
(Go)
Sep 17, 2026
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
High
CVE-2026-61672
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
High
CVE-2026-61833
was published
for
zotregistry.dev/zot/v2
(Go)
Sep 18, 2026
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
High
CVE-2026-58197
was published
for
github.com/stacklok/toolhive
(Go)
Sep 18, 2026
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
High
CVE-2026-81505
was published
for
github.com/frain-dev/convoy
(Go)
Sep 18, 2026
Perses's project query parameter authorization bypass exposes cross-project resources
High
CVE-2026-63458
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
High
CVE-2026-63199
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Perses's unvalidated project parameter enables filesystem path traversal
High
CVE-2026-63445
was published
for
github.com/perses/perses
(Go)
Sep 18, 2026
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
High
GHSA-xwmw-prc4-v3cr
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Obot: Server-Side Request Forgery via remote MCP server URL
High
GHSA-jgh3-fggc-mcpm
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API