GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,084
Maven
5,000+
npm
4,981
NuGet
825
pip
4,418
Pub
12
RubyGems
988
Rust
1,162
Swift
50
Unreviewed advisories
All unreviewed
5,000+
3,084 advisories
Filter by severity
Gokapi has privilege escalation with auth token
Moderate
CVE-2026-29060
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has Stored XSS in SVG Hotlinks
High
CVE-2026-28683
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Gokapi has Data Leak in Upload Status Stream
Moderate
CVE-2026-28682
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Critical
CVE-2026-27944
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 5, 2026
Agentgateway is missing parameter sanitization in MCP to OpenAPI conversion
Moderate
GHSA-v2x6-wwfw-r2rq
was published
for
github.com/agentgateway/agentgateway
(Go)
Mar 5, 2026
Sliver is Vulnerable to Authenticated Nil-Pointer Dereference through its Handlers
Low
CVE-2026-29781
was published
for
github.com/bishopfox/sliver
(Go)
Mar 5, 2026
Docker CLI Plugins: Uncontrolled Search Path Element Leads to Local Privilege Escalation on Windows
High
CVE-2025-15558
was published
for
github.com/docker/cli
(Go)
Mar 5, 2026
ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover
High
CVE-2026-29192
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication
High
CVE-2026-29193
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint
Critical
CVE-2026-29191
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check
Moderate
CVE-2026-29188
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 4, 2026
Netmaker Vulnerable to Denial of Service via Server Shutdown Endpoint
High
CVE-2026-29771
was published
for
github.com/gravitl/netmaker
(Go)
Mar 4, 2026
SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint
Critical
CVE-2026-29183
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 4, 2026
traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
High
CVE-2026-29054
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
Nuclio Shell Runtime Command Injection Leading to Privilege Escalation
High
CVE-2026-29042
was published
for
github.com/nuclio/nuclio
(Go)
Mar 4, 2026
lxd's non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints
Moderate
CVE-2026-3351
was published
for
github.com/canonical/lxd
(Go)
Mar 4, 2026
Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)
High
CVE-2026-26999
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS
Moderate
CVE-2026-26998
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
SiYuan's direct SQL Query API accessible to Reader-level users enables unauthorized database access
Moderate
CVE-2026-29073
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 3, 2026
Rancher Backup Operator pod's logs leak S3 tokens
Moderate
CVE-2025-62879
was published
for
github.com/rancher/backup-restore-operator
(Go)
Mar 3, 2026
Rancher cloud credentials can be used through proxy API by users without access
Critical
CVE-2021-25320
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user
High
GHSA-hwm2-4ph6-w6m5
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher's weave CNI password is not configured when a cluster is created from an RKE template
Moderate
CVE-2022-21951
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Critical
CVE-2022-31247
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
Rancher doesn't properly sanitize credentials in cluster template answers
Critical
CVE-2021-36783
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API