GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,032 advisories
Filter by severity
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Moderate
CVE-2026-67448
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Moderate
CVE-2026-67447
was published
for
github.com/axllent/mailpit
(Go)
Aug 20, 2026
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Moderate
CVE-2026-55187
was published
for
github.com/axllent/mailpit
(Go)
Jun 19, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Moderate
CVE-2026-48824
was published
for
github.com/axllent/mailpit
(Go)
Jul 1, 2026
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Moderate
CVE-2026-45712
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Moderate
CVE-2026-45711
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Moderate
CVE-2026-45709
was published
for
github.com/axllent/mailpit
(Go)
May 19, 2026
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Moderate
CVE-2026-39835
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data
Moderate
CVE-2026-65959
was published
for
vitess.io/vitess
(Go)
Aug 18, 2026
Gitea release asset dumps permit path traversal through crafted names
Moderate
CVE-2026-28705
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea tracked-time deletion is not scoped to the requested issue
Moderate
CVE-2026-25782
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea exposes tracked time entries without repository authorization
Moderate
CVE-2026-20909
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
Grafana Tempo vulnerable to an out-of-memory crash
Moderate
CVE-2026-27878
was published
for
github.com/grafana/tempo
(Go)
Jun 19, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Moderate
CVE-2026-55067
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Moderate
CVE-2026-55064
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Moderate
CVE-2026-55834
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Aug 28, 2026
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
Moderate
CVE-2026-55569
was published
for
github.com/aquaproj/aqua/v2
(Go)
Aug 28, 2026
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Moderate
CVE-2026-54746
was published
for
github.com/hatchet-dev/hatchet
(Go)
Aug 28, 2026
go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)
Moderate
CVE-2026-55828
was published
for
go.qbee.io/transport
(Go)
Jun 19, 2026
Cloudreve's remote download file paths can escape the selected destination directory
Moderate
GHSA-w8j7-39hp-8x59
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
ProTip!
Advisories are also available from the
GraphQL API