GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,751
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
371 advisories
Filter by severity
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Low
GHSA-rf68-8gjr-36q7
was published
for
github.com/nezhahq/nezha
(Go)
Sep 15, 2026
rclone: http backend forwards custom/auth headers to a different host on redirect
Low
CVE-2026-88013
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
Low
CVE-2025-24978
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Low
CVE-2026-73087
was published
for
github.com/amir20/dozzle
(Go)
Sep 8, 2026
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
netfoil vulnerable to improper handling of untrusted DoH response data
Low
GHSA-4ph6-mjv7-3fq6
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Aug 24, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Low
GHSA-22w5-2fxg-vrwx
was published
for
github.com/opentofu/opentofu
(Go)
Aug 20, 2026
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Low
GHSA-h58c-xccx-75m3
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing
Low
CVE-2026-61712
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
Low
CVE-2026-54787
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 31, 2026
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Low
CVE-2026-50568
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API
Low
CVE-2026-58511
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Low
CVE-2026-55984
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
Low
CVE-2026-58434
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Low
CVE-2026-58438
was published
for
gitea.dev
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API