Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

271 advisories

Loading
Gitea draft releases and attachments are exposed without write permission High
CVE-2026-27660 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea forwarded-proto validation allows canonical URL spoofing High
CVE-2026-27779 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data High
CVE-2026-25712 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases High
CVE-2026-24690 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers High
CVE-2026-53832 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
Filestash allows attackers to escalate privileges via sending a crafted request High
CVE-2026-50891 was published for github.com/mickael-kerjean/filestash (Go) Jun 15, 2026
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components High
CVE-2026-50884 was published for github.com/statping-ng/statping-ng (Go) Jun 15, 2026
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion High
CVE-2026-53831 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
Spring for GraphQL: Annotation Detection Vulnerability High
CVE-2026-41856 was published for org.springframework.graphql:spring-graphql (Maven) Jun 11, 2026
MLflow: trace API endpoints lack proper authorization validators High
CVE-2026-8147 was published for mlflow (pip) Jul 2, 2026
0x00-sys Credited to 0x00-sys
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
Spring Data REST has Improper Access Control in its JSON Patch Implementation High
CVE-2026-41728 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
berkdedekarginoglu Credited to berkdedekarginoglu
MCP Ruby SDK: Ruby SSE Session Poisoning High
CVE-2026-67431 was published for mcp (RubyGems) Jul 30, 2026
srikanthramu Credited to srikanthramu
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration High
CVE-2026-41006 was published for org.springframework.hateoas:spring-hateoas (Maven) Jun 9, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private High
CVE-2026-24451 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Repository Visibility Manipulation via Git Push Options High
CVE-2026-58437 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF High
CVE-2026-50132 was published for @budibase/server (npm) Jun 22, 2026
VishaaLlKumaaRr Credited to VishaaLlKumaaRr
ProTip! Advisories are also available from the GraphQL API