Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,608 advisories

Loading
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA Low
CVE-2026-55785 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI High
CVE-2026-55784 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read High
CVE-2026-55874 was published for github.com/seaweedfs/seaweedfs (Go) Aug 28, 2026
47Cid Credited to 47Cid
TA-MU-TA Credited to TA-MU-TA
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply High
CVE-2026-55764 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits High
CVE-2026-55763 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337 and fbsobreira fbsobreira fbsobreira
41Baloo Credited to 41Baloo
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL High
CVE-2026-55245 was published for github.com/maximhq/bifrost/core (Go) Aug 28, 2026
tonghuaroot Credited to tonghuaroot
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption Low
CVE-2026-55588 was published for oras.land/oras (Go) Aug 28, 2026
aditya19200 Credited to aditya19200
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment Moderate
CVE-2026-55067 was published for code.vikunja.io/api (Go) Aug 28, 2026
voraci0us Credited to voraci0us
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id High
CVE-2026-55066 was published for code.vikunja.io/api (Go) Aug 28, 2026
hoangperry Credited to hoangperry
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key High
CVE-2026-55065 was published for code.vikunja.io/api (Go) Aug 28, 2026
KadirArslan Credited to KadirArslan
AntarikshaAkhileshSharma Credited to AntarikshaAkhileshSharma
Vikunja has a project duplication bypasses write-permission check on the target parent project Moderate
CVE-2026-54766 was published for code.vikunja.io/api (Go) Aug 28, 2026
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none Moderate
CVE-2026-55834 was published for github.com/pocket-id/pocket-id/backend (Go) Aug 28, 2026
geo-chen Credited to geo-chen
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory Moderate
CVE-2026-55569 was published for github.com/aquaproj/aqua/v2 (Go) Aug 28, 2026
zerodaybugs Credited to zerodaybugs
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) Critical
CVE-2026-54755 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
KubeVela Terraform remote loader DoS via unbounded file read High
CVE-2026-55108 was published for github.com/oam-dev/kubevela (Go) Aug 28, 2026
hnts Credited to hnts
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe Moderate
CVE-2026-54746 was published for github.com/hatchet-dev/hatchet (Go) Aug 28, 2026
sajdakabir Credited to sajdakabir
ProTip! Advisories are also available from the GraphQL API