Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,715 advisories

Loading
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods High
CVE-2026-73667 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ksankeerth Credited to ksankeerth
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints High
CVE-2026-73841 was published for github.com/openchoreo/openchoreo (Go) Sep 2, 2026
ihopenre-eng Credited to ihopenre-eng
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection High
CVE-2026-67445 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths High
CVE-2026-72921 was published for github.com/seaweedfs/seaweedfs (Go) Sep 2, 2026
KadirArslan Credited to KadirArslan
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling High
CVE-2026-67446 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db High
CVE-2026-59832 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 2, 2026
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content High
CVE-2026-59834 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 2, 2026
mountainousmolehill Credited to mountainousmolehill and Kairos-T Kairos-T Kairos-T
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation High
CVE-2026-84304 was published for google.golang.org/grpc (Go) Sep 1, 2026
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI High
CVE-2026-55784 was published for github.com/free5gc/ausf (Go) Aug 28, 2026
jaimealruiz Credited to jaimealruiz and jav1er8 jav1er8 jav1er8
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read High
CVE-2026-55874 was published for github.com/seaweedfs/seaweedfs (Go) Aug 28, 2026
47Cid Credited to 47Cid
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply High
CVE-2026-55764 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances High
CVE-2026-55761 was published for github.com/portainer/portainer (Go) Aug 28, 2026
um3b0shi Credited to um3b0shi
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits High
CVE-2026-55763 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337 and fbsobreira fbsobreira fbsobreira
41Baloo Credited to 41Baloo
Incus has a project restriction bypass in instance copy across projects High
CVE-2026-55622 was published for github.com/lxc/incus/v7/cmd/incusd (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Incus has a project restriction bypass for custom volume copy across projects High
CVE-2026-55621 was published for github.com/lxc/incus (Go) Aug 28, 2026
antifob Credited to antifob and stgraber stgraber stgraber
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL High
CVE-2026-55245 was published for github.com/maximhq/bifrost/core (Go) Aug 28, 2026
tonghuaroot Credited to tonghuaroot
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id High
CVE-2026-55066 was published for code.vikunja.io/api (Go) Aug 28, 2026
hoangperry Credited to hoangperry
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key High
CVE-2026-55065 was published for code.vikunja.io/api (Go) Aug 28, 2026
KadirArslan Credited to KadirArslan
KubeVela Terraform remote loader DoS via unbounded file read High
CVE-2026-55108 was published for github.com/oam-dev/kubevela (Go) Aug 28, 2026
hnts Credited to hnts
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check High
GHSA-mf7q-r4rv-jv94 was published for github.com/crossplane/crossplane-runtime/v2 (Go) Aug 27, 2026
tonghuaroot Credited to tonghuaroot and bugbunny-research bugbunny-research bugbunny-research
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport High
CVE-2026-55637 was published for github.com/geiserx/genieacs-mcp (Go) Aug 25, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts High
CVE-2026-55092 was published for github.com/aquasecurity/trivy (Go) Aug 25, 2026
ikkebr Credited to ikkebr
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files High
CVE-2026-55677 was published for github.com/labstack/echo (Go) Aug 25, 2026
a-tt-om Credited to a-tt-om and oran-gugu oran-gugu oran-gugu
ProTip! Advisories are also available from the GraphQL API