Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,575 advisories

Loading
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport High
CVE-2026-55637 was published for github.com/geiserx/genieacs-mcp (Go) Aug 25, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts High
CVE-2026-55092 was published for github.com/aquasecurity/trivy (Go) Aug 25, 2026
ikkebr Credited to ikkebr
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files High
CVE-2026-55677 was published for github.com/labstack/echo (Go) Aug 25, 2026
a-tt-om Credited to a-tt-om and oran-gugu oran-gugu oran-gugu
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist High
CVE-2026-55580 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
sonirico Credited to sonirico
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable High
CVE-2026-55581 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab, useworld, and sonirico useworld useworld
sonirico sonirico
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias High
CVE-2026-55582 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab and sonirico sonirico sonirico
Cloudreve's remote download file paths can escape the selected destination directory Moderate
GHSA-w8j7-39hp-8x59 was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
jinhao-huang Credited to jinhao-huang
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint Moderate
GHSA-vx2m-jpxr-xv7w was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
riodrwn Credited to riodrwn
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation High
CVE-2026-55477 was published for github.com/mhsanaei/3x-ui/v2 (Go) Aug 24, 2026
itsamirhn Credited to itsamirhn
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key Moderate
GHSA-w67g-5rqw-f597 was published for github.com/gorilla/websocket (Go) Aug 24, 2026
netfoil vulnerable to improper handling of untrusted DoH response data Low
GHSA-4ph6-mjv7-3fq6 was published for github.com/tinfoil-factory/netfoil (Go) Aug 24, 2026
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding High
CVE-2026-77354 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS High
CVE-2026-76905 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation High
CVE-2026-64679 was published for github.com/runatlantis/atlantis (Go) Aug 21, 2026
shblue21 Credited to shblue21
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Moderate
CVE-2026-67448 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
arpitjain099 Credited to arpitjain099
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Moderate
CVE-2026-67447 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
rexpository Credited to rexpository
Fleet: ORDER BY column injection on activity list endpoints Low
GHSA-rxhg-vcww-2mpw was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
axel-corsiez Credited to axel-corsiez
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs Moderate
GHSA-q9c5-pp7m-fm2g was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
offset Credited to offset
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database High
CVE-2026-54245 was published for github.com/fleetdm/fleet (Go) Aug 20, 2026
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution Moderate
CVE-2026-54168 was published for github.com/openshift-pipelines/pipelines-as-code (Go) Aug 20, 2026
chmouel Credited to chmouel
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header High
CVE-2026-54167 was published for github.com/openshift-pipelines/pipelines-as-code (Go) Aug 20, 2026
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI Moderate
CVE-2026-54162 was published for github.com/alexandre-daubois/ember (Go) Aug 20, 2026
alexandre-daubois Credited to alexandre-daubois
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings Low
GHSA-h58c-xccx-75m3 was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison Low
GHSA-8fxq-53rx-ph5f was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
ProTip! Advisories are also available from the GraphQL API