GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,624 advisories
Filter by severity
libp2p nodes vulnerable to attack using large RSA keys
High
CVE-2023-39533
was published
for
github.com/libp2p/go-libp2p
(Go)
Aug 9, 2023
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
High
CVE-2026-84304
was published
for
google.golang.org/grpc
(Go)
Sep 1, 2026
Gitea pre-receive hook scanner errors allow branch-protection bypass
Critical
CVE-2026-27780
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea draft releases and attachments are exposed without write permission
High
CVE-2026-27660
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing
High
CVE-2026-27779
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea release asset dumps permit path traversal through crafted names
Moderate
CVE-2026-28705
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry
Critical
CVE-2026-26232
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass
Critical
CVE-2026-26247
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea tracked-time deletion is not scoped to the requested issue
Moderate
CVE-2026-25782
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data
High
CVE-2026-25712
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections
Critical
CVE-2026-26292
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea git grep searches allow server resource exhaustion
High
CVE-2026-26307
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea primary email ownership bypass allows cross-user email changes
High
CVE-2026-27657
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases
High
CVE-2026-24690
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths
Critical
CVE-2026-25718
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields
Critical
CVE-2026-22547
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea exposes tracked time entries without repository authorization
Moderate
CVE-2026-20909
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API
High
CVE-2026-42151
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
High
CVE-2026-48491
was published
for
github.com/traefik/traefik/v2
(Go)
Jun 16, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
High
CVE-2026-55784
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
High
CVE-2026-55874
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API