Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,624 advisories

Loading
libp2p nodes vulnerable to attack using large RSA keys High
CVE-2023-39533 was published for github.com/libp2p/go-libp2p (Go) Aug 9, 2023
marten-seemann Credited to marten-seemann and simonmorley simonmorley simonmorley
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation High
CVE-2026-84304 was published for google.golang.org/grpc (Go) Sep 1, 2026
Gitea pre-receive hook scanner errors allow branch-protection bypass Critical
CVE-2026-27780 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea draft releases and attachments are exposed without write permission High
CVE-2026-27660 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing High
CVE-2026-27779 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea release asset dumps permit path traversal through crafted names Moderate
CVE-2026-28705 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry Critical
CVE-2026-26232 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass Critical
CVE-2026-26247 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea tracked-time deletion is not scoped to the requested issue Moderate
CVE-2026-25782 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data High
CVE-2026-25712 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections Critical
CVE-2026-26292 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea git grep searches allow server resource exhaustion High
CVE-2026-26307 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea primary email ownership bypass allows cross-user email changes High
CVE-2026-27657 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases High
CVE-2026-24690 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths Critical
CVE-2026-25718 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields Critical
CVE-2026-22547 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea exposes tracked time entries without repository authorization Moderate
CVE-2026-20909 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API High
CVE-2026-42151 was published for github.com/prometheus/prometheus (Go) May 5, 2026
brettgervasoni Credited to brettgervasoni and noren95 noren95 noren95
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass High
CVE-2026-48491 was published for github.com/traefik/traefik/v2 (Go) Jun 16, 2026
kamil-sawicki Credited to kamil-sawicki and westonsteimel westonsteimel westonsteimel
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r, ncw, and 0x0sky ncw ncw
0x0sky 0x0sky
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI High
CVE-2026-55784 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read High
CVE-2026-55874 was published for github.com/seaweedfs/seaweedfs (Go) Aug 28, 2026
47Cid Credited to 47Cid
TA-MU-TA Credited to TA-MU-TA
ProTip! Advisories are also available from the GraphQL API