Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15 advisories

Loading
Gogs Directory Traversal High
CVE-2018-20303 was published for gogs.io/gogs (Go) May 14, 2022
cookesan Credited to cookesan
Git credentials are exposed in Atlantis logs High
CVE-2024-52009 was published for github.com/runatlantis/atlantis (Go) Nov 8, 2024
niooss-ledger Credited to niooss-ledger and cookesan cookesan cookesan
Duplicate Advisory: Hackney has an Allocation of Resources Without Limits or Throttling vulnerabilit High
GHSA-76v6-f83q-pxvh was published for hackney (Erlang) May 26, 2026 withdrawn
cookesan Credited to cookesan
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing High
CVE-2026-49451 was published for Microsoft.OpenAPI (NuGet) Jun 30, 2026
baywet Credited to baywet, cookesan, Falco20019, and mahsa-lamiyan cookesan cookesan
Falco20019 Falco20019 mahsa-lamiyan mahsa-lamiyan
Integer Overflow in go-jose High
CVE-2016-9123 was published for github.com/square/go-jose (Go) Jun 23, 2021
cookesan Credited to cookesan
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268) High
CVE-2024-22198 was published for github.com/0xJacky/Nginx-UI (Go) Jan 11, 2024
jorgectf Credited to jorgectf, Hintay, and cookesan Hintay Hintay
cookesan cookesan
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269) High
CVE-2024-22197 was published for github.com/0xJacky/Nginx-UI (Go) Jan 11, 2024
jorgectf Credited to jorgectf, Hintay, and cookesan Hintay Hintay
cookesan cookesan
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270) High
CVE-2024-22196 was published for github.com/0xJacky/Nginx-UI (Go) Jan 11, 2024
jorgectf Credited to jorgectf, Hintay, and cookesan Hintay Hintay
cookesan cookesan
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF High
CVE-2024-23828 was published for github.com/0xJacky/Nginx-UI (Go) Jan 29, 2024
Elleuch-x1 Credited to Elleuch-x1, 0xJacky, and cookesan 0xJacky 0xJacky
cookesan cookesan
fg0x0 Credited to fg0x0 and cookesan cookesan cookesan
Astro: Reflected XSS via unescaped slot name High
CVE-2026-50146 was published for astro (npm) Jun 16, 2026
floudeciel Credited to floudeciel and cookesan cookesan cookesan
Astro: Host header SSRF in prerendered error page fetch High
CVE-2026-54299 was published for astro (npm) Jun 16, 2026
5ud0er Credited to 5ud0er and cookesan cookesan cookesan
OctoPrint has possible file exfiltration via query parameters on upload endpoints High
CVE-2026-54134 was published for OctoPrint (pip) Jun 23, 2026
seankohjs Credited to seankohjs, jacopotediosi, and cookesan jacopotediosi jacopotediosi
cookesan cookesan
Pig-Tail Credited to Pig-Tail and cookesan cookesan cookesan
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data High
GHSA-p7mv-53f2-4cwj was published for github.com/cometbft/cometbft (Go) Nov 6, 2024
corverroos Credited to corverroos, cookesan, and simonmorley cookesan cookesan
simonmorley simonmorley
ProTip! Advisories are also available from the GraphQL API