GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
79 advisories
Filter by severity
Gitea draft releases and attachments are exposed without write permission
High
CVE-2026-27660
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing
High
CVE-2026-27779
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data
High
CVE-2026-25712
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases
High
CVE-2026-24690
was published
for
code.gitea.io/gitea
(Go)
Jul 3, 2026
Incus has a project restriction bypass in instance copy across projects
High
CVE-2026-55622
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Aug 28, 2026
Incus has a project restriction bypass for custom volume copy across projects
High
CVE-2026-55621
was published
for
github.com/lxc/incus
(Go)
Aug 28, 2026
Filestash allows attackers to escalate privileges via sending a crafted request
High
CVE-2026-50891
was published
for
github.com/mickael-kerjean/filestash
(Go)
Jun 15, 2026
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
High
CVE-2026-50884
was published
for
github.com/statping-ng/statping-ng
(Go)
Jun 15, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
High
CVE-2026-52810
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
High
CVE-2026-58422
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Visibility Manipulation via Git Push Options
High
CVE-2026-58437
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Caddy: Windows `file_server` path authorization bypass via encoded backslash
High
CVE-2026-52844
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54628
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags
High
CVE-2026-50138
was published
for
goshs.de/goshs/v2
(Go)
Jul 1, 2026
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
High
CVE-2026-49824
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
High
CVE-2026-49823
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
High
CVE-2026-49822
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
High
GHSA-7m8x-qg2j-4m3v
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
High
GHSA-vgrc-hq28-p3xp
was published
for
github.com/apernet/hysteria/core/v2
(Go)
Jun 26, 2026
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
High
CVE-2026-28699
was published
for
code.gitea.io/gitea
(Go)
Jun 16, 2026
Caddy Defender trusted proxy client IP bypass
High
CVE-2026-46415
was published
for
pkg.jsn.cam/caddy-defender
(Go)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API