Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

217 advisories

Loading
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation High
CVE-2026-55477 was published for github.com/mhsanaei/3x-ui/v2 (Go) Aug 24, 2026
itsamirhn Credited to itsamirhn
BuildKit: Custom frontend could bypass Seccomp/AppArmor Moderate
CVE-2026-61711 was published for github.com/moby/buildkit (Go) Aug 19, 2026
Alex0Young Credited to Alex0Young
package pkcs12: Authentication bypass in Decode functions Moderate
GHSA-mpwr-8vm7-h73f was published for software.sslmate.com/src/go-pkcs12 (Go) Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest Moderate
CVE-2026-45099 was published for github.com/gruntwork-io/terragrunt (Go) Aug 17, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure Moderate
CVE-2026-53551 was published for github.com/free5gc/ausf (Go) Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks Moderate
CVE-2026-50569 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure Critical
CVE-2026-53713 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
rudrakhp Credited to rudrakhp and dashingDragon dashingDragon dashingDragon
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection High
CVE-2026-44300 was published for github.com/opencost/opencost (Go) Jul 14, 2026
b0b0haha Credited to b0b0haha
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) High
CVE-2026-50553 was published for github.com/enchant97/note-mark/backend (Go) Jul 9, 2026
tonghuaroot Credited to tonghuaroot, Yunkaiwjs, and enchant97 Yunkaiwjs Yunkaiwjs
enchant97 enchant97
Gitea repository creation accepts insufficiently validated fields Critical
CVE-2026-22547 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Incus has an arbitrary file write on its client due to trusted image hash Critical
CVE-2026-48769 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Jun 26, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has an argument injection in backup compression algorithm leading to AFW and ACE Critical
CVE-2026-48755 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Jun 26, 2026
antifob Credited to antifob and stgraber stgraber stgraber
OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering Moderate
CVE-2026-53541 was published for github.com/OliveTin/OliveTin (Go) Jun 24, 2026
iconnnjka Credited to iconnnjka
Gogs has the ability to import local repositories via Mirror Settings High
CVE-2026-52801 was published for gogs.io/gogs (Go) Jun 23, 2026
KKC73 Credited to KKC73
Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected) Low
CVE-2026-44778 was published for github.com/inspektor-gadget/inspektor-gadget (Go) Jun 22, 2026
Gogs has a Denial of Service in repository/wiki file listing web pages Moderate
CVE-2025-64719 was published for gogs.io/gogs (Go) Jun 22, 2026
0xless Credited to 0xless
containerd CRI checkpoint restore CDI annotation smuggling High
CVE-2026-53492 was published for github.com/containerd/containerd/v2 (Go) Jun 19, 2026
robertprast Credited to robertprast
vnth4nhnt Credited to vnth4nhnt
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode High
CVE-2026-57209 was published for github.com/dadrus/heimdall (Go) Jun 18, 2026
tikket1 Credited to tikket1
Heimdall: IP Spoofing via Unvalidated Forwarding Headers High
CVE-2026-57210 was published for https://github.com/dadrus/heimdall (Go) Jun 18, 2026
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs) High
CVE-2026-53999 was published for github.com/radius-project/radius (Go) Jun 12, 2026
b0b0haha Credited to b0b0haha and j311yl0v3u j311yl0v3u j311yl0v3u
ProTip! Advisories are also available from the GraphQL API