Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

521 advisories

Loading
Gitea pre-receive hook scanner errors allow branch-protection bypass Critical
CVE-2026-27780 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 authorization codes can be reused after expiry Critical
CVE-2026-26232 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea OAuth2 PKCE S256 verifier bypass Critical
CVE-2026-26247 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea LFS mirror operations bypass migration HTTP transport protections Critical
CVE-2026-26292 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea template repository generation follows unsafe filesystem paths Critical
CVE-2026-25718 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea repository creation accepts insufficiently validated fields Critical
CVE-2026-22547 was published for code.gitea.io/gitea (Go) Jul 3, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) Critical
CVE-2026-54755 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
MCP Toolbox for Databases has an Origin Validation Error Critical
CVE-2026-11624 was published for github.com/googleapis/mcp-toolbox (Go) Jun 13, 2026
Withdrawn Advisory: go-mysql affected by go.uuid's Predictable UUID Identifiers Critical
GHSA-rc7v-65v6-m2v3 was published for github.com/go-mysql-org/go-mysql (Go) Oct 28, 2024 withdrawn
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import Critical
CVE-2026-54061 was published for github.com/dgraph-io/dgraph/v25 (Go) Aug 20, 2026
u-ktdi Credited to u-ktdi
Pelican Web UI Affected by a Privilege Escalation Attack Critical
CVE-2026-42571 was published for github.com/pelicanplatform/pelican (Go) May 4, 2026
bbockelm Credited to bbockelm, h2zh, brianaydemir, jhiemstrawisc, matyasselmeci, and williamnswanson h2zh h2zh
brianaydemir brianaydemir jhiemstrawisc jhiemstrawisc matyasselmeci matyasselmeci williamnswanson williamnswanson
New API: Integer overflow in quota billing yields negative charges (self-crediting) Critical
CVE-2026-71479 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388 and Calcium-Ion Calcium-Ion Calcium-Ion
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation Critical
CVE-2026-64859 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
August829 Credited to August829
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution Critical
CVE-2026-53476 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication Critical
CVE-2026-53475 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands Critical
CVE-2026-53474 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation Critical
CVE-2026-53471 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs Critical
CVE-2026-53470 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API Critical
CVE-2026-53469 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks Critical
CVE-2026-52813 was published for gogs.io/gogs (Go) Jun 23, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
ProTip! Advisories are also available from the GraphQL API