Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

18 advisories

Loading
CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data High
GHSA-p7mv-53f2-4cwj was published for github.com/cometbft/cometbft (Go) Nov 6, 2024
corverroos Credited to corverroos, cookesan, and simonmorley cookesan cookesan
simonmorley simonmorley
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
CVE-2026-73564 was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
Ollama Server Vulnerable to Denial of Service (DoS) Attack High
CVE-2025-1975 was published for github.com/ollama/ollama (Go) May 16, 2025
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string High
CVE-2026-46377 was published for github.com/tomwright/dasel/v3 (Go) May 19, 2026
kq5y Credited to kq5y
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE High
CVE-2026-41643 was published for github.com/osrg/gobgp/v4 (Go) Apr 29, 2026
bacon251 Credited to bacon251
Incus Vulnerable to Panic via Snapshot Bounds Check High
CVE-2026-40251 was published for github.com/lxc/incus/v6/cmd/incusd (Go) May 4, 2026
stamparm Credited to stamparm and stgraber stgraber stgraber
github.com/buger/jsonparser has a denial of service vulnerability High
CVE-2026-32285 was published for github.com/buger/jsonparser (Go) Mar 18, 2026
westonsteimel Credited to westonsteimel
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller High
CVE-2026-40886 was published for github.com/argoproj/argo-workflows/v3 (Go) Apr 23, 2026
thevilledev Credited to thevilledev
Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode High
CVE-2026-4427 was published for github.com/jackc/pgproto3/v2 (Go) Mar 19, 2026 withdrawn
Denial of service in github.com/jackc/pgproto3/v2 High
CVE-2026-32286 was published for github.com/jackc/pgproto3/v2 (Go) Mar 18, 2026
Out-of-Bounds Slice Access in free5GC CHF Leading to DoS High
CVE-2026-32937 was published for github.com/free5gc/chf (Go) Mar 18, 2026
LinZiyuu Credited to LinZiyuu
gosaml2 CBC Padding Panic — Unauthenticated Process Crash High
GHSA-hwqm-qvj9-4jr2 was published for github.com/russellhaering/gosaml2 (Go) Mar 18, 2026
xclow3n Credited to xclow3n
Fiber panics when fiber.Ctx.BodyParser parses invalid range index High
CVE-2025-48075 was published for github.com/gofiber/fiber/v2 (Go) May 22, 2025
Batleram Credited to Batleram, sixcolors, efectn, ReneWerner87, and gaby sixcolors sixcolors
efectn efectn ReneWerner87 ReneWerner87 gaby gaby
golang.org/x/net/html Improper Validation of Array Index vulnerability High
CVE-2018-17848 was published for golang.org/x/net (Go) May 13, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service High
CVE-2018-12018 was published for github.com/ethereum/go-ethereum (Go) May 14, 2022
Improper Input Validation in GoGo Protobuf High
CVE-2021-3121 was published for github.com/gogo/protobuf (Go) Mar 28, 2022
Improper Validation of Array Index in GJSON High
CVE-2020-36067 was published for github.com/tidwall/gjson (Go) Feb 6, 2023
ProTip! Advisories are also available from the GraphQL API