Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,624 advisories

Loading
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation High
CVE-2026-84304 was published for google.golang.org/grpc (Go) Sep 1, 2026
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI High
CVE-2026-55784 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read High
CVE-2026-55874 was published for github.com/seaweedfs/seaweedfs (Go) Aug 28, 2026
47Cid Credited to 47Cid
TA-MU-TA Credited to TA-MU-TA
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply High
CVE-2026-55764 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits High
CVE-2026-55763 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337 and fbsobreira fbsobreira fbsobreira
41Baloo Credited to 41Baloo
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL High
CVE-2026-55245 was published for github.com/maximhq/bifrost/core (Go) Aug 28, 2026
tonghuaroot Credited to tonghuaroot
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment Moderate
CVE-2026-55067 was published for code.vikunja.io/api (Go) Aug 28, 2026
voraci0us Credited to voraci0us
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id High
CVE-2026-55066 was published for code.vikunja.io/api (Go) Aug 28, 2026
hoangperry Credited to hoangperry
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key High
CVE-2026-55065 was published for code.vikunja.io/api (Go) Aug 28, 2026
KadirArslan Credited to KadirArslan
AntarikshaAkhileshSharma Credited to AntarikshaAkhileshSharma
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none Moderate
CVE-2026-55834 was published for github.com/pocket-id/pocket-id/backend (Go) Aug 28, 2026
geo-chen Credited to geo-chen
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory Moderate
CVE-2026-55569 was published for github.com/aquaproj/aqua/v2 (Go) Aug 28, 2026
zerodaybugs Credited to zerodaybugs
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) Critical
CVE-2026-54755 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
KubeVela Terraform remote loader DoS via unbounded file read High
CVE-2026-55108 was published for github.com/oam-dev/kubevela (Go) Aug 28, 2026
hnts Credited to hnts
ProTip! Advisories are also available from the GraphQL API