Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,095 advisories

Loading
Obot: MCP Registry API readable without authentication Moderate
GHSA-pr6h-vr44-xq8j was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools Moderate
CVE-2026-77339 was published for github.com/f1bonacc1/process-compose (Go) Sep 18, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets Moderate
CVE-2026-63406 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body Moderate
CVE-2026-63405 was published for github.com/anycable/anycable (Go) Sep 18, 2026
de3erve-hunter Credited to de3erve-hunter
PhucQuan Credited to PhucQuan
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic Moderate
CVE-2026-61794 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
PhucQuan Credited to PhucQuan
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass Moderate
CVE-2026-77281 was published for github.com/caddyserver/caddy/v2 (Go) Sep 18, 2026
WhiskerEnt Credited to WhiskerEnt
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning Moderate
CVE-2026-81871 was published for go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc (Go) Sep 17, 2026
pellared Credited to pellared and MrAlias MrAlias MrAlias
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing Moderate
CVE-2026-85732 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
manus-use Credited to manus-use
Netmaker has a boolean‑based SQL Injection Moderate
CVE-2026-32599 was published for github.com/gravitl/netmaker (Go) Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions Moderate
CVE-2026-76081 was published for github.com/zitadel/zitadel (Go) Sep 14, 2026
AyushParkara Credited to AyushParkara, IAM-marco, and livio-a IAM-marco IAM-marco
livio-a livio-a
ZITADEL: Auto-linking by email: IdP-side email verification is not checked Moderate
CVE-2026-56666 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, livio-a, IAM-marco, and ayadlin livio-a livio-a
IAM-marco IAM-marco ayadlin ayadlin
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider Moderate
CVE-2026-56665 was published for github.com/zitadel/zitadel (Go) Sep 11, 2026
Android-Login-Analysis Credited to Android-Login-Analysis, IAM-marco, livio-a, and Punisher100 IAM-marco IAM-marco
livio-a livio-a Punisher100 Punisher100
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace Moderate
CVE-2026-88014 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
manus-use Credited to manus-use and ncw ncw ncw
rclone local: crafted Range request against a translated symlink panics (DoS) Moderate
CVE-2026-88015 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
rclone: source object names can escape the configured root on upload Moderate
CVE-2026-88046 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
Traefik: ForwardAuth identity spoofing via dot-form header alias Moderate
CVE-2026-88011 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
velgusgus599 Credited to velgusgus599
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded Moderate
CVE-2026-88012 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ShadMalloy Credited to ShadMalloy
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows Moderate
CVE-2026-59162 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
webhookd: Unrestricted HTTP Header to Shell Variable Injection Moderate
CVE-2026-59157 was published for github.com/ncarlier/webhookd (Go) Sep 9, 2026
GimmyDatBeeR Credited to GimmyDatBeeR
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service Moderate
CVE-2026-53495 was published for github.com/containerd/containerd (Go) Sep 9, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint Moderate
CVE-2025-58363 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
kosmosec Credited to kosmosec
LF Edge eKuiper: SSRF in External Service Moderate
CVE-2025-24979 was published for github.com/lf-edge/ekuiper/v2 (Go) Sep 9, 2026
TheMostKnown Credited to TheMostKnown
ProTip! Advisories are also available from the GraphQL API