GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
366 advisories
Filter by severity
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Low
CVE-2026-42350
was published
for
github.com/akuity/kargo
(Go)
Aug 27, 2026
netfoil vulnerable to improper handling of untrusted DoH response data
Low
GHSA-4ph6-mjv7-3fq6
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Aug 24, 2026
Fleet: ORDER BY column injection on activity list endpoints
Low
GHSA-rxhg-vcww-2mpw
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 20, 2026
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Low
GHSA-22w5-2fxg-vrwx
was published
for
github.com/opentofu/opentofu
(Go)
Aug 20, 2026
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Low
GHSA-h58c-xccx-75m3
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
BuildKit has a possible runtime DoS via unbounded group parsing
Low
CVE-2026-61712
was published
for
github.com/moby/buildkit
(Go)
Aug 19, 2026
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
Low
CVE-2026-10722
was published
for
github.com/cilium/ebpf
(Go)
Jun 3, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
Low
CVE-2026-54787
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 31, 2026
Weaviate has an Improper Authorization issue
Low
CVE-2026-11500
was published
for
github.com/weaviate/weaviate
(Go)
Jun 8, 2026
grepai Uses a Broken or Risky Cryptographic Algorithm
Low
CVE-2026-11481
was published
for
github.com/yoanbernabeu/grepai
(Go)
Jun 8, 2026
grepai Uses a Broken or Risky Cryptographic Algorithm
Low
CVE-2026-11479
was published
for
github.com/yoanbernabeu/grepai
(Go)
Jun 8, 2026
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Low
CVE-2026-50568
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
songquanpeng one-api has an issue that results in business logic errors
Low
CVE-2026-11465
was published
for
github.com/songquanpeng/one-api
(Go)
Jun 8, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API
Low
CVE-2026-58511
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
Low
CVE-2026-55984
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Metadata Remains Accessible After Access Revocation
Low
CVE-2026-58434
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
Low
CVE-2026-58445
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API