GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
1,187 advisories
Filter by severity
In Soft Serve, an authenticated repo import can clone server-local private repositories
High
CVE-2026-33353
was published
for
github.com/charmbracelet/soft-serve
(Go)
Mar 19, 2026
Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG
High
CVE-2026-33344
was published
for
github.com/dagu-org/dagu
(Go)
Mar 19, 2026
Ella Core panics on malformed NGAP Location Report
High
CVE-2026-33282
was published
for
github.com/ellanetworks/core
(Go)
Mar 19, 2026
Juju has unauthorized access to out-of-scope Kubernetes secrets
High
CVE-2026-32693
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
High
CVE-2026-33252
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
pgproto3: Negative field length panics in DataRow.Decode
High
CVE-2026-4427
was published
for
github.com/jackc/pgproto3/v2
(Go)
Mar 19, 2026
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
High
GHSA-q382-vc8q-7jhj
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
Unsigned SAML LogoutRequest Acceptance in gosaml2
High
GHSA-pcgw-qcv5-h8ch
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 18, 2026
gosaml2 CBC Padding Panic — Unauthenticated Process Crash
High
GHSA-hwqm-qvj9-4jr2
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 18, 2026
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
High
GHSA-479m-364c-43vc
was published
for
github.com/russellhaering/goxmldsig
(Go)
Mar 18, 2026
free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques
High
CVE-2026-33192
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
High
CVE-2026-33191
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass
High
CVE-2026-33203
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference
High
CVE-2026-33064
was published
for
github.com/free5gc/udm
(Go)
Mar 18, 2026
free5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface Conversion
High
CVE-2026-33063
was published
for
github.com/free5gc/ausf
(Go)
Mar 18, 2026
free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list Parameter
High
CVE-2026-33062
was published
for
github.com/free5gc/nrf
(Go)
Mar 18, 2026
Out-of-Bounds Slice Access in free5GC CHF Leading to DoS
High
CVE-2026-32937
was published
for
github.com/free5gc/chf
(Go)
Mar 18, 2026
Heimdall: Path received via Envoy gRPC corrupted when containing query string
High
CVE-2026-32811
was published
for
github.com/dadrus/heimdall
(Go)
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
High
GHSA-jqcq-xjh3-6g23
was published
for
github.com/jackc/pgproto3/v2
(Go)
Mar 18, 2026
Denial of service in github.com/buger/jsonparser
High
GHSA-6g7g-w4f8-9c9x
was published
for
github.com/buger/jsonparser
(Go)
Mar 18, 2026
Denial of service in github.com/shamaton/msgpack
High
GHSA-h9q6-hc68-35rp
was published
for
github.com/shamaton/msgpack/v2
(Go)
Mar 18, 2026
Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS
High
CVE-2026-32254
was published
for
github.com/cloudnativelabs/kube-router/v2
(Go)
Mar 17, 2026
Fullchain's Invalid NetworkPolicy enables a malicious actor to pivot into another namespace
High
CVE-2026-32769
was published
for
github.com/ctfer-io/fullchain
(Go)
Mar 16, 2026
Romeo is vulnerable to Archive Slip due to missing checks in sanitization
High
CVE-2026-32805
was published
for
github.com/ctfer-io/romeo/webserver
(Go)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API