Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,091 advisories

Loading
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs Critical
CVE-2026-73843 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
JanakaSandaruwan Credited to JanakaSandaruwan
SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the... Moderate Unreviewed
CVE-2026-82650 was published Aug 30, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables High
GHSA-cc2g-26rw-g997 was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
Craft CMS: Authenticated leak of secret environment variables Moderate
CVE-2026-72782 was published for craftcms/cms (Composer) Aug 6, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Moderate
CVE-2026-70606 was published for electron (npm) Aug 5, 2026
rushitgit Credited to rushitgit
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted High
CVE-2026-67427 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
proot-distro has a Container Isolation Bypass via Crafted Restore Archive High
CVE-2026-54727 was published for proot-distro (pip) Jul 29, 2026
x0root Credited to x0root
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default High
CVE-2026-54504 was published for @andrea9293/mcp-documentation-server (npm) Jul 15, 2026
mcfly-zzh Credited to mcfly-zzh
ViewComponent: Reused Component Instances Retain Stale Render Context Moderate
CVE-2026-54497 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters Moderate
CVE-2026-54495 was published for github.com/open-feature/open-feature-operator (Go) Jul 15, 2026
0xVijay Credited to 0xVijay
Steeltoe's static JWKS cache shared across schemes and never invalidated Moderate
CVE-2026-50202 was published for Steeltoe.Security.Authentication.CloudFoundryBase (NuGet) Jul 2, 2026
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts Moderate
GHSA-6c4r-g249-wv3c was published for openclaw (npm) Jul 2, 2026
anshumanbh Credited to anshumanbh
rexpository Credited to rexpository
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path High
CVE-2026-54096 was published for github.com/filebrowser/filebrowser (Go) Jun 12, 2026
quart27219 Credited to quart27219, kimdu0, and hacdias kimdu0 kimdu0
hacdias hacdias
j4xT Credited to j4xT
ProTip! Advisories are also available from the GraphQL API