GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
164 advisories
Filter by severity
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Moderate
CVE-2026-55064
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Moderate
CVE-2026-54746
was published
for
github.com/hatchet-dev/hatchet
(Go)
Aug 28, 2026
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Critical
CVE-2026-54523
was published
for
github.com/kyverno/kyverno
(Go)
Aug 26, 2026
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Moderate
GHSA-q9c5-pp7m-fm2g
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Moderate
CVE-2026-54168
was published
for
github.com/openshift-pipelines/pipelines-as-code
(Go)
Aug 20, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users
Moderate
CVE-2026-64866
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
High
CVE-2026-54719
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
Gitea: Unauthorized Access to Labels of Private Organizations
High
CVE-2026-25038
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
Low
CVE-2026-58434
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
Moderate
CVE-2026-50105
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
Low
CVE-2026-58438
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea has insufficient permission checks for Composer package source links
High
CVE-2026-27771
was published
for
code.gitea.io/gitea
(Go)
Jul 17, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Moderate
CVE-2026-53718
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
High
CVE-2026-61549
was published
for
github.com/woodpecker-ci/woodpecker
(Go)
Jul 14, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
High
GHSA-7rx3-5wx3-5v76
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate
Moderate
CVE-2026-53602
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 9, 2026
Kite has an authenticated cluster RBAC bypass in /api/v1/overview
Moderate
CVE-2026-53487
was published
for
github.com/zxh326/kite
(Go)
Jul 7, 2026
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
Moderate
CVE-2026-55433
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
Moderate
CVE-2026-55432
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Critical
CVE-2026-49445
was published
for
github.com/cilium/cilium
(Go)
Jul 6, 2026
ProTip!
Advisories are also available from the
GraphQL API