Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

29 advisories

Loading
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) Moderate
CVE-2026-58428 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
AWS API MCP File Access Restriction Bypass Moderate
CVE-2026-4270 was published for awslabs-aws-api-mcp-server (pip) Mar 17, 2026
Gitea allows attackers to add attachments with forbidden file extensions High
CVE-2025-68939 was published for code.gitea.io/gitea (Go) Dec 26, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key Critical
CVE-2024-58136 was published for yiisoft/yii2 (Composer) Apr 10, 2025
ProTip! Advisories are also available from the GraphQL API