Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

507 advisories

Loading
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution Critical
CVE-2026-53476 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication Critical
CVE-2026-53475 was published for github.com/kubev2v/assisted-migration-agent (Go) Jun 10, 2026
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands Critical
CVE-2026-53474 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation Critical
CVE-2026-53471 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs Critical
CVE-2026-53470 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API Critical
CVE-2026-53469 was published for github.com/kubev2v/migration-planner (Go) Jun 10, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks Critical
CVE-2026-52813 was published for gogs.io/gogs (Go) Jun 23, 2026
Aikido-Security Credited to Aikido-Security, JorianWoltjer, reindaelman, and grumpinout1 JorianWoltjer JorianWoltjer
reindaelman reindaelman grumpinout1 grumpinout1
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Critical
CVE-2026-73080 was published for github.com/seaweedfs/seaweedfs (Go) Aug 11, 2026
KadirArslan Credited to KadirArslan
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys Critical
CVE-2026-39832 was published for golang.org/x/crypto (Go) Jun 25, 2026
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware Critical
CVE-2026-65600 was published for github.com/traefik/traefik (Go) Aug 6, 2026
C-h4ck-0 Credited to C-h4ck-0
Rancher vulnerable to command injection through unsanitized YAML parameter Critical
CVE-2026-44939 was published for github.com/rancher/rancher (Go) Jul 1, 2026
Ibonok Credited to Ibonok
0xVijay Credited to 0xVijay
Wings exposes node configuration secrets through egg configuration-file templating Critical
CVE-2026-52855 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
robertdrakedennis Credited to robertdrakedennis
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite Critical
CVE-2026-64863 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) Critical
CVE-2026-62325 was published for github.com/patrickhener/goshs/v2 (Go) Jul 28, 2026
yukikamome316 Credited to yukikamome316
Gitea: Public-only repository tokens can update private PR head branches Critical
CVE-2026-58443 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ohxorud-dev Credited to ohxorud-dev and bircni bircni bircni
kamil-sawicki Credited to kamil-sawicki
rz1027 Credited to rz1027
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
Gitea Remember-Me Token Theft Not Invalidating Attacker Session Critical
CVE-2026-56750 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path Critical
GHSA-g53w-w6mj-hrpp was published for github.com/Kuadrant/mcp-gateway (Go) May 19, 2026
Bhuvanesh66 Credited to Bhuvanesh66
ProTip! Advisories are also available from the GraphQL API