GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,153
Maven
5,000+
npm
5,000+
NuGet
861
pip
4,451
Pub
12
RubyGems
991
Rust
1,179
Swift
50
Unreviewed advisories
All unreviewed
5,000+
3,153 advisories
Filter by severity
Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings
Moderate
CVE-2026-32320
was published
for
github.com/ellanetworks/core
(Go)
Mar 12, 2026
Ella Core vulnerable to Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload
High
CVE-2026-32319
was published
for
github.com/ellanetworks/core
(Go)
Mar 12, 2026
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
High
CVE-2026-32246
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
Tinyauth's OIDC authorization codes are not bound to client on token exchange
Moderate
CVE-2026-32245
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
Traefik: HTTP/2 frames can cause a running server to panic
High
GHSA-4hjq-9h5c-252j
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 12, 2026
AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass
Critical
CVE-2026-32136
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Mar 12, 2026
SiYuan has a Full-Read SSRF via /api/network/forwardProxy
High
CVE-2026-32110
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 12, 2026
OliveTin's email argument makes compliance harder, enables log injection
Moderate
GHSA-xx6g-43w2-9g6g
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
OliveTin Vulnerable to Unauthorized Action Output Disclosure via EventStream
High
CVE-2026-32102
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 12, 2026
Consul is vulnerable to arbitrary file read when configured with Kubernetes authentication
Moderate
CVE-2026-2808
was published
for
github.com/hashicorp/consul
(Go)
Mar 12, 2026
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
High
CVE-2026-31892
was published
for
github.com/argoproj/argo-workflows
(Go)
Mar 11, 2026
Anytype Heart's gRPC API client challenge verification can be bypassed on localhost
Low
CVE-2026-31863
was published
for
github.com/anyproto/anytype-cli
(Go)
Mar 11, 2026
Cosmos EVM: incorrect state handling during nested EVM execution paths
Critical
GHSA-54gx-3cgr-7mfm
was published
for
github.com/cosmos/evm
(Go)
Mar 11, 2026
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Moderate
CVE-2026-29777
was published
for
github.com/traefik/traefik/v3
(Go)
Mar 11, 2026
Unauthorized access to Argo Workflows Template
High
CVE-2026-28229
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Mar 11, 2026
Quill has DoS via unbounded read of HTTP response body during notarization
Moderate
CVE-2026-31960
was published
for
github.com/anchore/quill
(Go)
Mar 11, 2026
Quill has unbounded memory allocation via unvalidated size fields in Mach-O binary parsing
Moderate
CVE-2026-31961
was published
for
github.com/anchore/quill
(Go)
Mar 11, 2026
Quill vulnerable to SSRF via unvalidated URL from Apple notarization log retrieval
Moderate
CVE-2026-31959
was published
for
github.com/anchore/quill
(Go)
Mar 11, 2026
flagd Vulnerable to Allocation of Resources Without Limits or Throttling
High
CVE-2026-31866
was published
for
github.com/open-feature/flagd/flagd
(Go)
Mar 11, 2026
Terraform Provider for SendGrid: TLS Session Resumption Bypasses Certificate Authority Trust Store Modifications in Go
Critical
GHSA-j443-wcqq-xprh
was published
for
github.com/arslanbekov/terraform-provider-sendgrid
(Go)
Mar 11, 2026
OliveTin's unsafe parsing of UniqueTrackingId can be used to write files
High
CVE-2026-31817
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 11, 2026
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Moderate
CVE-2026-31809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
Moderate
CVE-2026-31807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required)
High
CVE-2026-31801
was published
for
zotregistry.dev/zot
(Go)
Mar 10, 2026
Envoy's global rate limit may crash when the response phase limit is enabled and the response phase request is failed directly
Moderate
CVE-2026-26330
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API