Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

164 advisories

Loading
AntarikshaAkhileshSharma Credited to AntarikshaAkhileshSharma
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe Moderate
CVE-2026-54746 was published for github.com/hatchet-dev/hatchet (Go) Aug 28, 2026
sajdakabir Credited to sajdakabir
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs Moderate
GHSA-q9c5-pp7m-fm2g was published for github.com/fleetdm/fleet/v4 (Go) Aug 20, 2026
offset Credited to offset
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution Moderate
CVE-2026-54168 was published for github.com/openshift-pipelines/pipelines-as-code (Go) Aug 20, 2026
chmouel Credited to chmouel
New API: Admin can reset passkeys for same-level or higher-privileged users Moderate
CVE-2026-64866 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
Mi0uno Credited to Mi0uno
anir0y Credited to anir0y
Gitea: Unauthorized Access to Labels of Private Organizations High
CVE-2026-25038 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Private Repository Metadata Remains Accessible After Access Revocation Low
CVE-2026-58434 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) Moderate
CVE-2026-50105 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Gitea has insufficient permission checks for Composer package source links High
CVE-2026-27771 was published for code.gitea.io/gitea (Go) Jul 17, 2026
DevNoScope Credited to DevNoScope
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass Moderate
CVE-2026-53718 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend High
CVE-2026-61549 was published for github.com/woodpecker-ci/woodpecker (Go) Jul 14, 2026
AnuragBathani Credited to AnuragBathani
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` High
GHSA-7rx3-5wx3-5v76 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
adamyordan Credited to adamyordan
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54629 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode Critical
CVE-2026-50006 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
nebula-mesh: Host revocation is not durable - blocked/offboarded hosts can regain a valid certificate Moderate
CVE-2026-53602 was published for github.com/forgekeep/nebula-mesh (Go) Jul 9, 2026
Kite has an authenticated cluster RBAC bypass in /api/v1/overview Moderate
CVE-2026-53487 was published for github.com/zxh326/kite (Go) Jul 7, 2026
DavidCarliez Credited to DavidCarliez
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers Moderate
CVE-2026-55433 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Coder's sub-agent app registration bypasses template port-sharing policy enforcement Moderate
CVE-2026-55432 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access Critical
CVE-2026-49445 was published for github.com/cilium/cilium (Go) Jul 6, 2026
0xch4z Credited to 0xch4z and moemen moemen moemen
ProTip! Advisories are also available from the GraphQL API