GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,521 advisories
Filter by severity
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Moderate
CVE-2026-53658
was published
for
github.com/hyperledger/fabric-ca
(Go)
Aug 14, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
High
CVE-2026-54917
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 12, 2026
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Moderate
CVE-2026-48786
was published
for
github.com/fleetdm/fleet/v4
(Go)
Aug 12, 2026
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Critical
CVE-2026-73080
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 11, 2026
go-git: Malicious reference names may modify files outside the reference storage
Moderate
CVE-2026-71557
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
go-git: Worktree operations may follow symlinks
High
CVE-2026-71556
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
High
CVE-2026-54763
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 6, 2026
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Critical
CVE-2026-65600
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
CVE-2026-67309
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Moderate
CVE-2026-54765
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Moderate
CVE-2026-71325
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Moderate
CVE-2026-54764
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
High
CVE-2026-71327
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Low
CVE-2026-71326
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
High
CVE-2026-71324
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
CVE-2026-65602
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 5, 2026
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
CVE-2026-65601
was published
for
Traefik
(Go)
Aug 5, 2026
rclone: Local Encoding Path Traversal
Moderate
CVE-2026-71313
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone archive extract allows S3 destination prefix escape via crafted archive paths
Moderate
CVE-2026-59732
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
High
CVE-2026-59733
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
High
CVE-2026-71312
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
ProTip!
Advisories are also available from the
GraphQL API