Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,578 advisories

Loading
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic Moderate
GHSA-3x6r-wxxg-53vv was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote High
CVE-2026-54572 was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Incomplete path validation allows backend root escape in serve restic High
CVE-2026-71309 was published for github.com/rclone/rclone (Go) Aug 5, 2026
CaubiLoureiro Credited to CaubiLoureiro and ncw ncw ncw
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote Low
GHSA-945v-v9p3-v5xw was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Verbose Stack Trace Disclosure in RC API Error Responses Low
GHSA-gwfq-86j8-7qhv was published for github.com/rclone/rclone (Go) Aug 5, 2026
SnailSploit Credited to SnailSploit and ncw ncw ncw
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
GHSA-7qf5-7ppr-87v8 was published for github.com/traefik/traefik/v3 (Go) Aug 1, 2026 withdrawn
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message Moderate
CVE-2026-54908 was published for github.com/pion/dtls/v3 (Go) Jul 31, 2026
Sean-Der Credited to Sean-Der and kajaaz kajaaz kajaaz
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
sigstore-go fails to check signature timestamps against a signing key's validity period Low
CVE-2026-54787 was published for github.com/sigstore/sigstore-go (Go) Jul 31, 2026
tnytown Credited to tnytown
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure Moderate
CVE-2026-53551 was published for github.com/free5gc/ausf (Go) Jul 31, 2026
0xVijay Credited to 0xVijay
thientd Credited to thientd
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
Wings exposes node configuration secrets through egg configuration-file templating Critical
CVE-2026-52855 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
robertdrakedennis Credited to robertdrakedennis
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check Moderate
CVE-2026-67438 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
Ayantaker Credited to Ayantaker
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output Moderate
CVE-2026-67439 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
offset Credited to offset
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) High
CVE-2026-67437 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
knight-yagami Credited to knight-yagami
netfoil: Incorrect block responses could lead to localhost traffic High
GHSA-xvg2-cgv6-6h7v was published for github.com/tinfoil-factory/netfoil (Go) Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
ZITADEL Users Can Self-Verify Email/Phone via API High
CVE-2026-54693 was published for github.com/zitadel/zitadel (Go) Jul 29, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
ProTip! Advisories are also available from the GraphQL API