Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

271 advisories

Loading
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
berkdedekarginoglu Credited to berkdedekarginoglu
MCP Ruby SDK: Ruby SSE Session Poisoning High
CVE-2026-67431 was published for mcp (RubyGems) Jul 30, 2026
srikanthramu Credited to srikanthramu
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private High
CVE-2026-24451 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Repository Visibility Manipulation via Git Push Options High
CVE-2026-58437 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service High
CVE-2026-58421 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54629 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54628 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
DIRAC: SQL injection and lack of access control in PilotManager service High
GHSA-7xw9-549r-8jrc was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
Gitea forwarded-proto validation allows canonical URL spoofing High
CVE-2026-27779 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea organization permission APIs expose hidden membership and private organization data High
CVE-2026-25712 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea pull request branch permission checks allow unauthorized updates and rebases High
CVE-2026-24690 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Gitea draft releases and attachments are exposed without write permission High
CVE-2026-27660 was published for code.gitea.io/gitea (Go) Jul 3, 2026
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance High
CVE-2026-53816 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion High
CVE-2026-53831 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority High
CVE-2026-53814 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
OpenClaw: Control UI locality spoofing could mint a durable admin device token High
CVE-2026-53817 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers High
CVE-2026-53832 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads High
CVE-2026-53810 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
ProTip! Advisories are also available from the GraphQL API