Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,634 advisories

Loading
cyberlanc3r Credited to cyberlanc3r
File Browser: Colliding username normalization gives two users the same home directory High
CVE-2026-62685 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup High
CVE-2026-55667 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
babakizo420 Credited to babakizo420 and lexdotdev lexdotdev lexdotdev
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim High
CVE-2026-54560 was published for github.com/cloudreve/Cloudreve/v4 (Go) Jul 20, 2026
EaEa0001 Credited to EaEa0001
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies High
GHSA-8qqm-fp2q-v734 was published for github.com/zalando/skipper (Go) Jul 17, 2026
sec-reex Credited to sec-reex
Gitea has insufficient permission checks for Composer package source links High
CVE-2026-27771 was published for code.gitea.io/gitea (Go) Jul 17, 2026
DevNoScope Credited to DevNoScope
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE High
CVE-2026-52833 was published for github.com/nuclio/nuclio (Go) Jul 16, 2026
j311yl0v3u Credited to j311yl0v3u and b0b0haha b0b0haha b0b0haha
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode High
CVE-2026-53714 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
cnvergence Credited to cnvergence, zirain, guydc, and dashingDragon zirain zirain
guydc guydc dashingDragon dashingDragon
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback High
CVE-2026-50285 was published for github.com/pomerium/pomerium (Go) Jul 15, 2026
bugbunny-research Credited to bugbunny-research
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS High
CVE-2026-50274 was published for github.com/DataDog/dd-trace-go (Go) Jul 15, 2026
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend High
CVE-2026-61549 was published for github.com/woodpecker-ci/woodpecker (Go) Jul 14, 2026
AnuragBathani Credited to AnuragBathani
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` High
GHSA-7rx3-5wx3-5v76 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
adamyordan Credited to adamyordan
nebula-mesh: Certificate revocation is never enforced at the mesh High
CVE-2026-61699 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
Pig-Tail Credited to Pig-Tail
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54629 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
nebula-mesh: Operator session tokens stored in plaintext in the database High
CVE-2026-53603 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths High
CVE-2026-53604 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware High
GHSA-mqxv-9rm6-w8qc was published for github.com/lin-snow/ech0 (Go) Jul 14, 2026
tonghuaroot Credited to tonghuaroot
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser High
CVE-2026-54448 was published for github.com/aquasecurity/trivy (Go) Jul 14, 2026
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services High
GHSA-pqg7-v6wh-3pfp was published for github.com/almeidapaulopt/tsdproxy (Go) Jul 14, 2026
yutu: Arbitrary File Write via MCP `caption-download` Tool High
CVE-2026-50158 was published for github.com/eat-pray-ai/yutu (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation High
CVE-2026-50141 was published for go.woodpecker-ci.org/woodpecker/v3 (Go) Jul 14, 2026
shivamkumarcyber Credited to shivamkumarcyber
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion High
CVE-2026-50125 was published for github.com/StacklokLabs/mkp (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode High
CVE-2026-50013 was published for github.com/SpectoLabs/hoverfly (Go) Jul 14, 2026
Kr1shna4garwal Credited to Kr1shna4garwal
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection High
CVE-2026-44300 was published for github.com/opencost/opencost (Go) Jul 14, 2026
b0b0haha Credited to b0b0haha
ProTip! Advisories are also available from the GraphQL API