GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
2,095 advisories
Filter by severity
Obot: MCP Registry API readable without authentication
Moderate
GHSA-pr6h-vr44-xq8j
was published
for
github.com/obot-platform/obot
(Go)
Sep 18, 2026
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
Moderate
CVE-2026-77339
was published
for
github.com/f1bonacc1/process-compose
(Go)
Sep 18, 2026
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
Moderate
CVE-2026-63406
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
Moderate
CVE-2026-63405
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Moderate
CVE-2026-61795
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
Moderate
CVE-2026-61794
was published
for
github.com/projectcapsule/capsule
(Go)
Sep 18, 2026
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
Moderate
CVE-2026-77281
was published
for
github.com/caddyserver/caddy/v2
(Go)
Sep 18, 2026
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Moderate
CVE-2026-81871
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
(Go)
Sep 17, 2026
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
Moderate
CVE-2026-85732
was published
for
oras.land/oras-go/v2
(Go)
Sep 17, 2026
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
Moderate
CVE-2026-61709
was published
for
github.com/openfga/openfga
(Go)
Sep 16, 2026
Netmaker has a boolean‑based SQL Injection
Moderate
CVE-2026-32599
was published
for
github.com/gravitl/netmaker
(Go)
Sep 15, 2026
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Moderate
CVE-2026-76081
was published
for
github.com/zitadel/zitadel
(Go)
Sep 14, 2026
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Moderate
CVE-2026-56666
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
Moderate
CVE-2026-56665
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
Moderate
CVE-2026-88014
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Moderate
CVE-2026-88016
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone local: crafted Range request against a translated symlink panics (DoS)
Moderate
CVE-2026-88015
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
rclone: source object names can escape the configured root on upload
Moderate
CVE-2026-88046
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
Traefik: ForwardAuth identity spoofing via dot-form header alias
Moderate
CVE-2026-88011
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Moderate
CVE-2026-88012
was published
for
github.com/traefik/traefik/v2
(Go)
Sep 10, 2026
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
Moderate
CVE-2026-59162
was published
for
github.com/xuri/excelize
(Go)
Sep 10, 2026
webhookd: Unrestricted HTTP Header to Shell Variable Injection
Moderate
CVE-2026-59157
was published
for
github.com/ncarlier/webhookd
(Go)
Sep 9, 2026
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
Moderate
CVE-2026-53495
was published
for
github.com/containerd/containerd
(Go)
Sep 9, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
Moderate
CVE-2025-58363
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
LF Edge eKuiper: SSRF in External Service
Moderate
CVE-2025-24979
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Sep 9, 2026
ProTip!
Advisories are also available from the
GraphQL API