GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,715 advisories
Filter by severity
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
High
CVE-2026-73667
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
High
CVE-2026-73841
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
High
CVE-2026-67445
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
High
CVE-2026-72921
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Sep 2, 2026
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
High
CVE-2026-67446
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
High
CVE-2026-59832
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 2, 2026
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
High
CVE-2026-59834
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 2, 2026
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
High
CVE-2026-84304
was published
for
google.golang.org/grpc
(Go)
Sep 1, 2026
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
High
CVE-2026-55784
was published
for
github.com/free5gc/ausf
(Go)
Aug 28, 2026
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
High
CVE-2026-55874
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
High
CVE-2026-55764
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
High
CVE-2026-55761
was published
for
github.com/portainer/portainer
(Go)
Aug 28, 2026
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
High
CVE-2026-55763
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
High
CVE-2026-55484
was published
for
github.com/guno1928/alos-http
(Go)
Aug 28, 2026
Incus has a project restriction bypass in instance copy across projects
High
CVE-2026-55622
was published
for
github.com/lxc/incus/v7/cmd/incusd
(Go)
Aug 28, 2026
Incus has a project restriction bypass for custom volume copy across projects
High
CVE-2026-55621
was published
for
github.com/lxc/incus
(Go)
Aug 28, 2026
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
High
CVE-2026-55245
was published
for
github.com/maximhq/bifrost/core
(Go)
Aug 28, 2026
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
High
CVE-2026-55066
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
High
CVE-2026-55065
was published
for
code.vikunja.io/api
(Go)
Aug 28, 2026
KubeVela Terraform remote loader DoS via unbounded file read
High
CVE-2026-55108
was published
for
github.com/oam-dev/kubevela
(Go)
Aug 28, 2026
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
High
GHSA-mf7q-r4rv-jv94
was published
for
github.com/crossplane/crossplane-runtime/v2
(Go)
Aug 27, 2026
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
High
CVE-2026-54563
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Aug 26, 2026
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
High
CVE-2026-55637
was published
for
github.com/geiserx/genieacs-mcp
(Go)
Aug 25, 2026
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
High
CVE-2026-55092
was published
for
github.com/aquasecurity/trivy
(Go)
Aug 25, 2026
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
High
CVE-2026-55677
was published
for
github.com/labstack/echo
(Go)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API