Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,629 advisories

Loading
New API: Admin can reset passkeys for same-level or higher-privileged users Moderate
CVE-2026-64866 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
Mi0uno Credited to Mi0uno
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging High
CVE-2026-64868 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
passer12 Credited to passer12
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation Critical
CVE-2026-64859 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
August829 Credited to August829
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access High
CVE-2026-54917 was published for github.com/seaweedfs/seaweedfs (Go) Aug 12, 2026
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint Moderate
CVE-2026-48786 was published for github.com/fleetdm/fleet/v4 (Go) Aug 12, 2026
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Critical
CVE-2026-73080 was published for github.com/seaweedfs/seaweedfs (Go) Aug 11, 2026
KadirArslan Credited to KadirArslan
go-git: Malicious reference names may modify files outside the reference storage Moderate
CVE-2026-71557 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
Saku0512 Credited to Saku0512
go-git: Worktree operations may follow symlinks High
CVE-2026-71556 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
kodareef5 Credited to kodareef5 and HughLewis20 HughLewis20 HughLewis20
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware Critical
CVE-2026-65600 was published for github.com/traefik/traefik (Go) Aug 6, 2026
C-h4ck-0 Credited to C-h4ck-0
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
CVE-2026-67309 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
B1gN0Se Credited to B1gN0Se
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Moderate
CVE-2026-54765 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
gooood4u Credited to gooood4u
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Moderate
CVE-2026-71325 was published for github.com/traefik/traefik (Go) Aug 6, 2026
ttzero25 Credited to ttzero25
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Moderate
CVE-2026-54764 was published for github.com/traefik/traefik (Go) Aug 6, 2026
Pig-Tail Credited to Pig-Tail
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking High
CVE-2026-71327 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool High
CVE-2026-71324 was published for github.com/traefik/traefik (Go) Aug 6, 2026
xclow3n Credited to xclow3n
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
CVE-2026-65602 was published for github.com/traefik/traefik/v3 (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd and james-yusuke james-yusuke james-yusuke
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
CVE-2026-65601 was published for Traefik (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd
rclone: Local Encoding Path Traversal Moderate
CVE-2026-71313 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone archive extract allows S3 destination prefix escape via crafted archive paths Moderate
CVE-2026-59732 was published for github.com/rclone/rclone (Go) Aug 5, 2026
Dangel165 Credited to Dangel165 and ncw ncw ncw
ProTip! Advisories are also available from the GraphQL API