GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
50
GitHub Actions
50
Go
3,679
Maven
5,000+
npm
5,000+
NuGet
932
pip
4,910
Pub
13
RubyGems
1,053
Rust
1,318
Swift
53
Unreviewed advisories
All unreviewed
5,000+
93 advisories
Filter by severity
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Low
CVE-2026-42875
was published
for
github.com/external-secrets/external-secrets
(Go)
May 5, 2026
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books
Moderate
CVE-2026-41572
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 25, 2026
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
High
CVE-2026-40248
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
High
CVE-2026-40247
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
High
CVE-2026-40246
was published
for
github.com/free5gc/udr
(Go)
Apr 14, 2026
Juju: CloudSpec method leaking cloud credentials
Critical
CVE-2026-5412
was published
for
github.com/juju/juju
(Go)
Apr 10, 2026
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
High
GHSA-4h9q-p5j4-xvvh
was published
for
github.com/lin-snow/ech0
(Go)
Apr 10, 2026
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`
High
CVE-2026-40259
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 10, 2026
monetr: Protected Transactions Deletable via PUT
Moderate
CVE-2026-39901
was published
for
github.com/monetr/monetr
(Go)
Apr 8, 2026
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
High
GHSA-46wh-3698-f2cx
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 29, 2026
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Moderate
CVE-2026-21724
was published
for
github.com/grafana/grafana
(Go)
Mar 26, 2026
Vikjuna: Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation
High
CVE-2026-33680
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
High
CVE-2026-33668
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
NATS JetStream has an authorization bypass through its Management API
Moderate
CVE-2026-33222
was published
for
github.com/nats-io/nats-server
(Go)
Mar 24, 2026
Juju has unauthorized update of out-of-scope Vault secrets
High
CVE-2026-32692
was published
for
github.com/juju/juju
(Go)
Mar 19, 2026
gRPC-Go has an authorization bypass via missing leading slash in :path
Critical
CVE-2026-33186
was published
for
google.golang.org/grpc
(Go)
Mar 18, 2026
SiYuan's renderSprig has a missing admin check that allows any user to read full workspace DB
Moderate
CVE-2026-32704
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 13, 2026
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning
Low
GHSA-q926-c743-49qj
was published
for
github.com/centrifugal/centrifugo
(Go)
Mar 13, 2026
SiYuan Vulnerable to Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
Critical
CVE-2026-30869
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 7, 2026
Rancher has downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)
Critical
CVE-2022-31247
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
INSATutorat has an authorization bypass vulnerability in its /api/admin/* endpoints
High
GHSA-xfx2-prg5-jq3g
was published
for
github.com/romitou/insatutorat
(Go)
Mar 1, 2026
Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration
High
GHSA-4jmp-x7mh-rgmr
was published
for
github.com/babylonlabs-io/finality-provider
(Go)
Dec 12, 2025
step-ca Has Improper Authorization Check for SSH Certificate Revocation
Moderate
CVE-2025-66406
was published
for
github.com/smallstep/certificates
(Go)
Dec 3, 2025
OpenFGA Improper Policy Enforcement
Moderate
CVE-2025-64751
was published
for
github.com/openfga/openfga
(Go)
Nov 20, 2025
File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function
High
CVE-2025-64523
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Nov 13, 2025
ProTip!
Advisories are also available from the
GraphQL API