Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,521 advisories

Loading
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access High
CVE-2026-54917 was published for github.com/seaweedfs/seaweedfs (Go) Aug 12, 2026
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint Moderate
CVE-2026-48786 was published for github.com/fleetdm/fleet/v4 (Go) Aug 12, 2026
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Critical
CVE-2026-73080 was published for github.com/seaweedfs/seaweedfs (Go) Aug 11, 2026
KadirArslan Credited to KadirArslan
go-git: Malicious reference names may modify files outside the reference storage Moderate
CVE-2026-71557 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
Saku0512 Credited to Saku0512
go-git: Worktree operations may follow symlinks High
CVE-2026-71556 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
kodareef5 Credited to kodareef5 and HughLewis20 HughLewis20 HughLewis20
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware Critical
CVE-2026-65600 was published for github.com/traefik/traefik (Go) Aug 6, 2026
C-h4ck-0 Credited to C-h4ck-0
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
CVE-2026-67309 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
B1gN0Se Credited to B1gN0Se
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Moderate
CVE-2026-54765 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
gooood4u Credited to gooood4u
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Moderate
CVE-2026-71325 was published for github.com/traefik/traefik (Go) Aug 6, 2026
ttzero25 Credited to ttzero25
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Moderate
CVE-2026-54764 was published for github.com/traefik/traefik (Go) Aug 6, 2026
Pig-Tail Credited to Pig-Tail
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking High
CVE-2026-71327 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool High
CVE-2026-71324 was published for github.com/traefik/traefik (Go) Aug 6, 2026
xclow3n Credited to xclow3n
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
CVE-2026-65602 was published for github.com/traefik/traefik/v3 (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd and james-yusuke james-yusuke james-yusuke
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
CVE-2026-65601 was published for Traefik (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd
rclone: Local Encoding Path Traversal Moderate
CVE-2026-71313 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone archive extract allows S3 destination prefix escape via crafted archive paths Moderate
CVE-2026-59732 was published for github.com/rclone/rclone (Go) Aug 5, 2026
Dangel165 Credited to Dangel165 and ncw ncw ncw
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
5ud0er Credited to 5ud0er and ncw ncw ncw
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution High
CVE-2026-71312 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
ProTip! Advisories are also available from the GraphQL API