GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,578 advisories
Filter by severity
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
Moderate
GHSA-3x6r-wxxg-53vv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
High
CVE-2026-54572
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Incomplete path validation allows backend root escape in serve restic
High
CVE-2026-71309
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
GHSA-7qf5-7ppr-87v8
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 1, 2026
•
withdrawn
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Moderate
CVE-2026-54908
was published
for
github.com/pion/dtls/v3
(Go)
Jul 31, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
Low
CVE-2026-54787
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 31, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Wings exposes node configuration secrets through egg configuration-file templating
Critical
CVE-2026-52855
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
Moderate
CVE-2026-67438
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
Moderate
CVE-2026-67439
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
High
CVE-2026-67437
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
netfoil: Incorrect block responses could lead to localhost traffic
High
GHSA-xvg2-cgv6-6h7v
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API
High
CVE-2026-54693
was published
for
github.com/zitadel/zitadel
(Go)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API