Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,629 advisories

Loading
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data High
GHSA-p7mv-53f2-4cwj was published for github.com/cometbft/cometbft (Go) Nov 6, 2024
corverroos Credited to corverroos, cookesan, and simonmorley cookesan cookesan
simonmorley simonmorley
Denial of Service in Go-Ethereum High
CVE-2022-23327 was published for github.com/ethereum/go-ethereum (Go) Mar 5, 2022
simonmorley Credited to simonmorley
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment Low
CVE-2025-29923 was published for github.com/redis/go-redis/v9 (Go) Mar 20, 2025
noren95 Credited to noren95
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts High
CVE-2026-53622 was published for github.com/traefik/traefik (Go) Jun 16, 2026
kamil-sawicki Credited to kamil-sawicki, westonsteimel, and rezmoss westonsteimel westonsteimel
rezmoss rezmoss
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass High
CVE-2026-48491 was published for github.com/traefik/traefik/v2 (Go) Jun 16, 2026
kamil-sawicki Credited to kamil-sawicki and westonsteimel westonsteimel westonsteimel
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization High
CVE-2026-48020 was published for github.com/traefik/traefik/v2 (Go) Jun 11, 2026
H4ck2 Credited to H4ck2
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow Moderate
CVE-2026-39835 was published for golang.org/x/crypto (Go) Jun 25, 2026
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data Moderate
CVE-2026-65959 was published for vitess.io/vitess (Go) Aug 18, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control Critical
CVE-2026-72920 was published for github.com/seaweedfs/seaweedfs (Go) Sep 2, 2026
KadirArslan Credited to KadirArslan
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop High
CVE-2026-43871 was published for apache/thrift (Composer) Jul 27, 2026
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db High
CVE-2026-59832 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 2, 2026
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content High
CVE-2026-59834 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 2, 2026
mountainousmolehill Credited to mountainousmolehill and Kairos-T Kairos-T Kairos-T
libp2p nodes vulnerable to attack using large RSA keys High
CVE-2023-39533 was published for github.com/libp2p/go-libp2p (Go) Aug 9, 2023
marten-seemann Credited to marten-seemann and simonmorley simonmorley simonmorley
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation High
CVE-2026-84304 was published for google.golang.org/grpc (Go) Sep 1, 2026
Gitea pre-receive hook scanner errors allow branch-protection bypass Critical
CVE-2026-27780 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea draft releases and attachments are exposed without write permission High
CVE-2026-27660 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing High
CVE-2026-27779 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea release asset dumps permit path traversal through crafted names Moderate
CVE-2026-28705 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry Critical
CVE-2026-26232 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass Critical
CVE-2026-26247 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea tracked-time deletion is not scoped to the requested issue Moderate
CVE-2026-25782 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data High
CVE-2026-25712 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections Critical
CVE-2026-26292 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea git grep searches allow server resource exhaustion High
CVE-2026-26307 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea primary email ownership bypass allows cross-user email changes High
CVE-2026-27657 was published for code.gitea.io/gitea (Go) Jul 3, 2026
ProTip! Advisories are also available from the GraphQL API