Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,796 advisories

Loading
Traefik entrypoint header-name sanitization bypassed via request trailers High
CVE-2026-88004 was published for github.com/traefik/traefik/v3 (Go) Sep 10, 2026
bipol4r Credited to bipol4r
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization High
CVE-2026-88008 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ihopenre-eng Credited to ihopenre-eng
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange High
CVE-2026-56668 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
thesecguy45 Credited to thesecguy45, cipher-creator, and wim07101993 cipher-creator cipher-creator
wim07101993 wim07101993
emp3r0r has an unauthenticated HTTP Polling DoS High
CVE-2026-61554 was published for github.com/jm33-m0/emp3r0r/core (Go) Sep 15, 2026
blankshiro Credited to blankshiro
Pocketbase: Unhandled panic in worker goroutines High
CVE-2026-82410 was published for github.com/pocketbase/pocketbase (Go) Sep 17, 2026
gigioneggiando Credited to gigioneggiando
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation High
CVE-2026-77403 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection High
CVE-2026-77404 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration High
CVE-2026-77406 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields High
CVE-2026-77407 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation High
CVE-2026-77410 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client High
CVE-2026-77412 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd and MirahImage MirahImage MirahImage
Pig-Tail Credited to Pig-Tail
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) High
CVE-2026-85731 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
CoreDNS: Unauthenticated memory exhaustion in custom transports High
CVE-2026-82399 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP High
CVE-2026-86003 was published for github.com/coredns/coredns (Go) Sep 17, 2026
thevilledev Credited to thevilledev
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement High
CVE-2026-61672 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
5ud0er Credited to 5ud0er
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion High
CVE-2026-61833 was published for zotregistry.dev/zot/v2 (Go) Sep 18, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement High
CVE-2026-58197 was published for github.com/stacklok/toolhive (Go) Sep 18, 2026
xxradar Credited to xxradar, ChrisJBurns, JAORMX, jhrozek, kantord, and eleftherias ChrisJBurns ChrisJBurns
JAORMX JAORMX jhrozek jhrozek kantord kantord eleftherias eleftherias
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials High
CVE-2026-81505 was published for github.com/frain-dev/convoy (Go) Sep 18, 2026
GrayOM Credited to GrayOM
Perses's project query parameter authorization bypass exposes cross-project resources High
CVE-2026-63458 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure High
CVE-2026-63199 was published for github.com/perses/perses (Go) Sep 18, 2026
ImDuong Credited to ImDuong
Perses's unvalidated project parameter enables filesystem path traversal High
CVE-2026-63445 was published for github.com/perses/perses (Go) Sep 18, 2026
bhilaire1a Credited to bhilaire1a
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion High
GHSA-xwmw-prc4-v3cr was published for github.com/obot-platform/obot (Go) Sep 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Obot: Server-Side Request Forgery via remote MCP server URL High
GHSA-jgh3-fggc-mcpm was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
ProTip! Advisories are also available from the GraphQL API