Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

79 advisories

Loading
Gitea draft releases and attachments are exposed without write permission High
CVE-2026-27660 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing High
CVE-2026-27779 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data High
CVE-2026-25712 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases High
CVE-2026-24690 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Filestash allows attackers to escalate privileges via sending a crafted request High
CVE-2026-50891 was published for github.com/mickael-kerjean/filestash (Go) Jun 15, 2026
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components High
CVE-2026-50884 was published for github.com/statping-ng/statping-ng (Go) Jun 15, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private High
CVE-2026-24451 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Repository Visibility Manipulation via Git Push Options High
CVE-2026-58437 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Caddy: Windows `file_server` path authorization bypass via encoded backslash High
CVE-2026-52844 was published for github.com/caddyserver/caddy (Go) Jun 16, 2026
Vincent550102 Credited to Vincent550102
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54629 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags High
CVE-2026-50138 was published for goshs.de/goshs/v2 (Go) Jul 1, 2026
black-shadow-007 Credited to black-shadow-007
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook High
CVE-2026-49824 was published for github.com/fission/fission (Go) Jun 30, 2026
j311yl0v3u Credited to j311yl0v3u, b0b0haha, and sanketsudake b0b0haha b0b0haha
sanketsudake sanketsudake
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook High
CVE-2026-49823 was published for github.com/fission/fission (Go) Jun 30, 2026
j311yl0v3u Credited to j311yl0v3u, b0b0haha, and sanketsudake b0b0haha b0b0haha
sanketsudake sanketsudake
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance High
CVE-2026-49822 was published for github.com/fission/fission (Go) Jun 30, 2026
j311yl0v3u Credited to j311yl0v3u, b0b0haha, and sanketsudake b0b0haha b0b0haha
sanketsudake sanketsudake
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec High
GHSA-7m8x-qg2j-4m3v was published for github.com/fission/fission (Go) Jun 30, 2026
FORIMOC Credited to FORIMOC, nnin-nnin, and sanketsudake nnin-nnin nnin-nnin
sanketsudake sanketsudake
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF High
GHSA-vgrc-hq28-p3xp was published for github.com/apernet/hysteria/core/v2 (Go) Jun 26, 2026
0xlally Credited to 0xlally
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication High
CVE-2026-28699 was published for code.gitea.io/gitea (Go) Jun 16, 2026
Alardiians Credited to Alardiians
Caddy Defender trusted proxy client IP bypass High
CVE-2026-46415 was published for pkg.jsn.cam/caddy-defender (Go) May 19, 2026
JasonLovesDoggo Credited to JasonLovesDoggo
ProTip! Advisories are also available from the GraphQL API