Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12 advisories

Loading
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources Moderate
GHSA-c534-2w9c-x7fm was published for github.com/zxh326/kite (Go) Jul 24, 2026
Eclipse Jetty: Path parameter traversal Moderate
CVE-2026-8384 was published for org.eclipse.jetty:jetty-util (Maven) Jul 22, 2026
jweny Credited to jweny
File Browser: Colliding username normalization gives two users the same home directory High
CVE-2026-62685 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
Eclso Credited to Eclso and ematipico ematipico ematipico
Cargo can be coerced to share credentials between registries Low
CVE-2026-5222 was published for cargo (Rust) Jun 26, 2026
christos-spearbit Credited to christos-spearbit, arlosi, weihanglo, ehuss, emilyalbini, cuviper, and Manishearth arlosi arlosi
weihanglo weihanglo ehuss ehuss emilyalbini emilyalbini cuviper cuviper Manishearth Manishearth
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765 Moderate
CVE-2025-66202 was published for astro (npm) Dec 8, 2025
zomaxsec Credited to zomaxsec
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass High
CVE-2025-64500 was published for symfony/http-foundation (Composer) Nov 12, 2025
cs278 Credited to cs278 and nicolas-grekas nicolas-grekas nicolas-grekas
mmudryi Credited to mmudryi and markiyanch markiyanch markiyanch
Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL Critical
GHSA-f54f-hr32-586f was published for browser-use (pip) May 3, 2025 withdrawn
ProTip! Advisories are also available from the GraphQL API