Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,032 advisories

Loading
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) Moderate
CVE-2026-73840 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) Moderate
CVE-2026-67448 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
arpitjain099 Credited to arpitjain099
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Moderate
CVE-2026-67447 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
rexpository Credited to rexpository
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms Moderate
CVE-2026-55187 was published for github.com/axllent/mailpit (Go) Jun 19, 2026
JLLeitschuh Credited to JLLeitschuh
KadirArslan Credited to KadirArslan
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs Moderate
CVE-2026-45711 was published for github.com/axllent/mailpit (Go) May 19, 2026
KadirArslan Credited to KadirArslan
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer Moderate
CVE-2026-45709 was published for github.com/axllent/mailpit (Go) May 19, 2026
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow Moderate
CVE-2026-39835 was published for golang.org/x/crypto (Go) Jun 25, 2026
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data Moderate
CVE-2026-65959 was published for vitess.io/vitess (Go) Aug 18, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Gitea release asset dumps permit path traversal through crafted names Moderate
CVE-2026-28705 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea tracked-time deletion is not scoped to the requested issue Moderate
CVE-2026-25782 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea exposes tracked time entries without repository authorization Moderate
CVE-2026-20909 was published for code.gitea.io/gitea (Go) Jul 3, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r, ncw, and 0x0sky ncw ncw
0x0sky 0x0sky
TA-MU-TA Credited to TA-MU-TA
Grafana Tempo vulnerable to an out-of-memory crash Moderate
CVE-2026-27878 was published for github.com/grafana/tempo (Go) Jun 19, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment Moderate
CVE-2026-55067 was published for code.vikunja.io/api (Go) Aug 28, 2026
voraci0us Credited to voraci0us
AntarikshaAkhileshSharma Credited to AntarikshaAkhileshSharma
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none Moderate
CVE-2026-55834 was published for github.com/pocket-id/pocket-id/backend (Go) Aug 28, 2026
geo-chen Credited to geo-chen
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory Moderate
CVE-2026-55569 was published for github.com/aquaproj/aqua/v2 (Go) Aug 28, 2026
zerodaybugs Credited to zerodaybugs
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe Moderate
CVE-2026-54746 was published for github.com/hatchet-dev/hatchet (Go) Aug 28, 2026
sajdakabir Credited to sajdakabir
go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination) Moderate
CVE-2026-55828 was published for go.qbee.io/transport (Go) Jun 19, 2026
ttzero25 Credited to ttzero25 and wwwvwwvwwwwwvwwvw wwwvwwvwwwwwvwwvw wwwvwwvwwwwwvwwvw
Cloudreve's remote download file paths can escape the selected destination directory Moderate
GHSA-w8j7-39hp-8x59 was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
jinhao-huang Credited to jinhao-huang
ProTip! Advisories are also available from the GraphQL API