GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,575
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,523
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,575 advisories
Filter by severity
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
High
CVE-2026-55637
was published
for
github.com/geiserx/genieacs-mcp
(Go)
Aug 25, 2026
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
High
CVE-2026-55092
was published
for
github.com/aquasecurity/trivy
(Go)
Aug 25, 2026
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
High
CVE-2026-55677
was published
for
github.com/labstack/echo
(Go)
Aug 25, 2026
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
High
CVE-2026-55580
was published
for
github.com/sonirico/mcp-shell
(Go)
Aug 25, 2026
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
High
CVE-2026-55581
was published
for
github.com/sonirico/mcp-shell
(Go)
Aug 25, 2026
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
High
CVE-2026-55582
was published
for
github.com/sonirico/mcp-shell
(Go)
Aug 25, 2026
Cloudreve's remote download file paths can escape the selected destination directory
Moderate
GHSA-w8j7-39hp-8x59
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Moderate
GHSA-vx2m-jpxr-xv7w
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
High
CVE-2026-55477
was published
for
github.com/mhsanaei/3x-ui/v2
(Go)
Aug 24, 2026
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
Moderate
GHSA-w67g-5rqw-f597
was published
for
github.com/gorilla/websocket
(Go)
Aug 24, 2026
netfoil vulnerable to improper handling of untrusted DoH response data
Low
GHSA-4ph6-mjv7-3fq6
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Aug 24, 2026
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
High
CVE-2026-77354
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
High
CVE-2026-76905
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
High
CVE-2026-64679
was published
for
github.com/runatlantis/atlantis
(Go)
Aug 21, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Moderate
GHSA-q9c5-pp7m-fm2g
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
High
CVE-2026-54245
was published
for
github.com/fleetdm/fleet
(Go)
Aug 20, 2026
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Moderate
CVE-2026-54168
was published
for
github.com/openshift-pipelines/pipelines-as-code
(Go)
Aug 20, 2026
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
High
CVE-2026-54167
was published
for
github.com/openshift-pipelines/pipelines-as-code
(Go)
Aug 20, 2026
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Low
GHSA-22w5-2fxg-vrwx
was published
for
github.com/opentofu/opentofu
(Go)
Aug 20, 2026
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Moderate
CVE-2026-54162
was published
for
github.com/alexandre-daubois/ember
(Go)
Aug 20, 2026
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Low
GHSA-h58c-xccx-75m3
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API