GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
521 advisories
Filter by severity
Gitea pre-receive hook scanner errors allow branch-protection bypass
Critical
CVE-2026-27780
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry
Critical
CVE-2026-26232
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass
Critical
CVE-2026-26247
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections
Critical
CVE-2026-26292
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths
Critical
CVE-2026-25718
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields
Critical
CVE-2026-22547
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Critical
CVE-2026-55068
was published
for
github.com/free5gc/free5gc
(Go)
Aug 28, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
Critical
CVE-2026-54755
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Critical
CVE-2026-54754
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Critical
CVE-2026-54523
was published
for
github.com/kyverno/kyverno
(Go)
Aug 26, 2026
MCP Toolbox for Databases has an Origin Validation Error
Critical
CVE-2026-11624
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 13, 2026
Withdrawn Advisory: go-mysql affected by go.uuid's Predictable UUID Identifiers
Critical
GHSA-rc7v-65v6-m2v3
was published
for
github.com/go-mysql-org/go-mysql
(Go)
Oct 28, 2024
•
withdrawn
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Critical
CVE-2026-54061
was published
for
github.com/dgraph-io/dgraph/v25
(Go)
Aug 20, 2026
Pelican Web UI Affected by a Privilege Escalation Attack
Critical
CVE-2026-42571
was published
for
github.com/pelicanplatform/pelican
(Go)
May 4, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting)
Critical
CVE-2026-71479
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Critical
CVE-2026-64859
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Critical
CVE-2026-53476
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Critical
CVE-2026-53475
was published
for
github.com/kubev2v/assisted-migration-agent
(Go)
Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Critical
CVE-2026-53474
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Critical
CVE-2026-53471
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Critical
CVE-2026-53470
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
Critical
CVE-2026-53469
was published
for
github.com/kubev2v/migration-planner
(Go)
Jun 10, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks
Critical
CVE-2026-52813
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
ProTip!
Advisories are also available from the
GraphQL API