GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
217 advisories
Filter by severity
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Critical
CVE-2026-55068
was published
for
github.com/free5gc/free5gc
(Go)
Aug 28, 2026
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
High
CVE-2026-55477
was published
for
github.com/mhsanaei/3x-ui/v2
(Go)
Aug 24, 2026
BuildKit: Custom frontend could bypass Seccomp/AppArmor
Moderate
CVE-2026-61711
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
package pkcs12: Authentication bypass in Decode functions
Moderate
GHSA-mpwr-8vm7-h73f
was published
for
software.sslmate.com/src/go-pkcs12
(Go)
Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Moderate
CVE-2026-45099
was published
for
github.com/gruntwork-io/terragrunt
(Go)
Aug 17, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Moderate
CVE-2026-50569
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Critical
CVE-2026-53713
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
High
CVE-2026-44300
was published
for
github.com/opencost/opencost
(Go)
Jul 14, 2026
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
High
CVE-2026-50553
was published
for
github.com/enchant97/note-mark/backend
(Go)
Jul 9, 2026
Gitea repository creation accepts insufficiently validated fields
Critical
CVE-2026-22547
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Incus has an arbitrary file write on its client due to trusted image hash
Critical
CVE-2026-48769
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
Incus has an argument injection in backup compression algorithm leading to AFW and ACE
Critical
CVE-2026-48755
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Jun 26, 2026
OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering
Moderate
CVE-2026-53541
was published
for
github.com/OliveTin/OliveTin
(Go)
Jun 24, 2026
Gogs has the ability to import local repositories via Mirror Settings
High
CVE-2026-52801
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)
Low
CVE-2026-44778
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Jun 22, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages
Moderate
CVE-2025-64719
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
containerd CRI checkpoint restore CDI annotation smuggling
High
CVE-2026-53492
was published
for
github.com/containerd/containerd/v2
(Go)
Jun 19, 2026
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Moderate
CVE-2026-54319
was published
for
github.com/daytonaio/daytona
(Go)
Jun 18, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
High
CVE-2026-57209
was published
for
github.com/dadrus/heimdall
(Go)
Jun 18, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
High
CVE-2026-57210
was published
for
https://github.com/dadrus/heimdall
(Go)
Jun 18, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
High
CVE-2026-53999
was published
for
github.com/radius-project/radius
(Go)
Jun 12, 2026
ProTip!
Advisories are also available from the
GraphQL API