GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,001 advisories
Filter by severity
package pkcs12: Authentication bypass in Decode functions
Moderate
GHSA-mpwr-8vm7-h73f
was published
for
software.sslmate.com/src/go-pkcs12
(Go)
Aug 17, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
Moderate
CVE-2026-55062
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
uniget CLI has an EDITOR Command Injection
Moderate
CVE-2026-55061
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Moderate
CVE-2026-45099
was published
for
github.com/gruntwork-io/terragrunt
(Go)
Aug 17, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
Moderate
CVE-2026-64865
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: Admin can reset passkeys for same-level or higher-privileged users
Moderate
CVE-2026-64866
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
Moderate
CVE-2026-52815
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Moderate
CVE-2026-39835
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Moderate
CVE-2026-73506
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
CVE-2026-73502
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Moderate
CVE-2026-48786
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 12, 2026
OpenShift Builder has a path traversal, allows command injection in privileged BuildContainer
Moderate
CVE-2024-7387
was published
for
github.com/openshift/builder
(Go)
Sep 17, 2024
go-git: Malicious reference names may modify files outside the reference storage
Moderate
CVE-2026-71557
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
Buildah allows arbitrary directory mount
Moderate
CVE-2024-9675
was published
for
github.com/containers/buildah
(Go)
Oct 9, 2024
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Moderate
CVE-2026-54765
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Moderate
CVE-2026-71325
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Moderate
CVE-2026-54764
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
CVE-2026-65602
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 5, 2026
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
GHSA-7m3p-wc52-rmc6
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
CVE-2026-65601
was published
for
Traefik
(Go)
Aug 5, 2026
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
GHSA-6mxq-jr92-3h2r
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
rclone: Local Encoding Path Traversal
Moderate
CVE-2026-71313
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone archive extract allows S3 destination prefix escape via crafted archive paths
Moderate
CVE-2026-59732
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API