GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
1,634 advisories
Filter by severity
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
High
CVE-2026-48126
was published
for
github.com/xyproto/algernon
(Go)
Jun 23, 2026
Gogs: LFS dedupe path leaks private repo content across tenants
High
CVE-2026-52812
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
High
CVE-2026-52810
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs's write-level collaborators can mutate admin-only repository settings via API
High
CVE-2026-52808
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
High
CVE-2026-52805
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs has the ability to import local repositories via Mirror Settings
High
CVE-2026-52801
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
High
CVE-2026-52800
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs Missing Authorization in Attachment Download
High
CVE-2026-52799
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Gogs has Stored XSS in `.ipynb` Preview
High
CVE-2026-52798
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Gogs has SSRF in webhook deliveries
High
CVE-2026-47267
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
High
CVE-2026-25119
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
High
GHSA-6vxv-wg6j-5qwp
was published
for
gogs.io/gogs
(Go)
Jun 19, 2026
Blocky DNSSEC validation bypass and validation-cache scope pollution
High
GHSA-x845-2f78-7v36
was published
for
github.com/0xERR0R/blocky
(Go)
Jun 19, 2026
containerd CRI checkpoint restore CDI annotation smuggling
High
CVE-2026-53492
was published
for
github.com/containerd/containerd/v2
(Go)
Jun 19, 2026
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
High
CVE-2026-53489
was published
for
github.com/containerd/containerd/v2
(Go)
Jun 19, 2026
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
High
CVE-2026-53488
was published
for
github.com/containerd/containerd
(Go)
Jun 19, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
High
GHSA-r46f-3rpw-hxrv
was published
for
github.com/gohugoio/hugo
(Go)
Jun 19, 2026
OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL
High
GHSA-q7j3-v8qv-22vq
was published
for
github.com/opentofu/opentofu
(Go)
Jun 19, 2026
Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
High
CVE-2026-55883
was published
for
github.com/tilt-dev/tilt
(Go)
Jun 19, 2026
Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
High
CVE-2026-55882
was published
for
github.com/tilt-dev/tilt
(Go)
Jun 19, 2026
MCP Toolbox for Databases: authenticated authorization bypass
High
CVE-2026-11719
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 18, 2026
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
High
CVE-2026-57209
was published
for
github.com/dadrus/heimdall
(Go)
Jun 18, 2026
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
High
CVE-2026-57210
was published
for
https://github.com/dadrus/heimdall
(Go)
Jun 18, 2026
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
High
CVE-2026-55672
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Docker MCP Gateway: Argument injection via OCI image label YAML
High
CVE-2026-55887
was published
for
github.com/docker/mcp-gateway
(Go)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API