Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,663 advisories

Loading
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts High
CVE-2026-35511 was published for github.com/authorizerdev/authorizer (Go) Aug 14, 2026
kodareef5 Credited to kodareef5
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
CVE-2026-73564 was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
CVE-2026-73509 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Oh My Posh: Arbitrary command execution via template injection in the path segment High
CVE-2026-73505 was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) High
CVE-2026-54526 was published for github.com/argoproj/argo-workflows (Go) Aug 13, 2026
fg0x0 Credited to fg0x0, 0xVijay, Joibel, and tonghuaroot 0xVijay 0xVijay
Joibel Joibel tonghuaroot tonghuaroot
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
Gogs: XSS in .ipynb files renderer due to outdated notebookjs High
GHSA-6vxv-wg6j-5qwp was published for gogs.io/gogs (Go) Jun 19, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
CVE-2026-73500 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
etcd: Watch API authorization bypass via open-ended range requests High
CVE-2026-73499 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access High
CVE-2026-54917 was published for github.com/seaweedfs/seaweedfs (Go) Aug 12, 2026
go-git: Worktree operations may follow symlinks High
CVE-2026-71556 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
kodareef5 Credited to kodareef5 and HughLewis20 HughLewis20 HughLewis20
Gophish contains a denial of service vulnerability High
CVE-2026-39904 was published for github.com/gophish/gophish (Go) Jun 22, 2026
ashikmd7 Credited to ashikmd7
Duplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware High
GHSA-rhg6-2vjh-j5qc was published for github.com/traefik/traefik/v2 (Go) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
CVE-2026-67309 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
B1gN0Se Credited to B1gN0Se
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass High
GHSA-7qf5-7ppr-87v8 was published for github.com/traefik/traefik/v3 (Go) Aug 1, 2026 withdrawn
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking High
CVE-2026-71327 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool High
CVE-2026-71324 was published for github.com/traefik/traefik (Go) Aug 6, 2026
xclow3n Credited to xclow3n
5ud0er Credited to 5ud0er and ncw ncw ncw
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution High
CVE-2026-71312 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote High
CVE-2026-54572 was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Incomplete path validation allows backend root escape in serve restic High
CVE-2026-71309 was published for github.com/rclone/rclone (Go) Aug 5, 2026
CaubiLoureiro Credited to CaubiLoureiro and ncw ncw ncw
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution High
CVE-2026-50163 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
anvanster Credited to anvanster and onelapahead onelapahead onelapahead
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
ProTip! Advisories are also available from the GraphQL API