GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,608 advisories
Filter by severity
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
Low
CVE-2026-55785
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
High
CVE-2026-55784
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
High
CVE-2026-55874
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Moderate
CVE-2026-55873
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
High
CVE-2026-55764
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
High
CVE-2026-55763
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
Incus has a project restriction bypass in instance copy across projects
High
CVE-2026-55622
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Aug 28, 2026
Incus has a project restriction bypass for custom volume copy across projects
High
CVE-2026-55621
was published
for
github.com/lxc/incus
(Go)
Aug 28, 2026
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
High
CVE-2026-55245
was published
for
github.com/maximhq/bifrost/core
(Go)
Aug 28, 2026
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
Low
CVE-2026-55588
was published
for
oras.land/oras
(Go)
Aug 28, 2026
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Critical
CVE-2026-55068
was published
for
github.com/free5gc/free5gc
(Go)
Aug 28, 2026
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Moderate
CVE-2026-55067
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
High
CVE-2026-55066
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
High
CVE-2026-55065
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Moderate
CVE-2026-55064
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja has a project duplication bypasses write-permission check on the target parent project
Moderate
CVE-2026-54766
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Moderate
CVE-2026-55834
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Aug 28, 2026
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
Moderate
CVE-2026-55569
was published
for
github.com/aquaproj/aqua/v2
(Go)
Aug 28, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
Critical
CVE-2026-54755
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Critical
CVE-2026-54754
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
KubeVela Terraform remote loader DoS via unbounded file read
High
CVE-2026-55108
was published
for
github.com/oam-dev/kubevela
(Go)
Aug 28, 2026
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Moderate
CVE-2026-54746
was published
for
github.com/hatchet-dev/hatchet
(Go)
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API