Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

371 advisories

Loading
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty Low
GHSA-rf68-8gjr-36q7 was published for github.com/nezhahq/nezha (Go) Sep 15, 2026
DavidCarliez Credited to DavidCarliez
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
LF Edge eKuiper: Self-XSS in External Service Creation Low
CVE-2025-24978 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher Low
CVE-2026-73087 was published for github.com/amir20/dozzle (Go) Sep 8, 2026
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter Low
CVE-2026-42350 was published for github.com/akuity/kargo (Go) Aug 27, 2026
PontusHanssen Credited to PontusHanssen, krancour, and rpelczar krancour krancour
rpelczar rpelczar
netfoil vulnerable to improper handling of untrusted DoH response data Low
GHSA-4ph6-mjv7-3fq6 was published for github.com/tinfoil-factory/netfoil (Go) Aug 24, 2026
Fleet: ORDER BY column injection on activity list endpoints Low
GHSA-rxhg-vcww-2mpw was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
axel-corsiez Credited to axel-corsiez
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings Low
GHSA-h58c-xccx-75m3 was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison Low
GHSA-8fxq-53rx-ph5f was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing Low
CVE-2026-61712 was published for github.com/moby/buildkit (Go) Aug 19, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote Low
GHSA-945v-v9p3-v5xw was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Verbose Stack Trace Disclosure in RC API Error Responses Low
GHSA-gwfq-86j8-7qhv was published for github.com/rclone/rclone (Go) Aug 5, 2026
SnailSploit Credited to SnailSploit and ncw ncw ncw
sigstore-go fails to check signature timestamps against a signing key's validity period Low
CVE-2026-54787 was published for github.com/sigstore/sigstore-go (Go) Jul 31, 2026
tnytown Credited to tnytown
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape Low
CVE-2026-50568 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API Low
CVE-2026-58511 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service Low
CVE-2026-55984 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
Gitea: Private Repository Metadata Remains Accessible After Access Revocation Low
CVE-2026-58434 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
ProTip! Advisories are also available from the GraphQL API