GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,666 advisories
Filter by severity
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
High
GHSA-fhgh-wq4q-r37x
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
High
CVE-2026-64868
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
High
CVE-2026-54526
was published
for
github.com/argoproj/argo-workflows
(Go)
Aug 13, 2026
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
High
CVE-2026-54917
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 12, 2026
go-git: Worktree operations may follow symlinks
High
CVE-2026-71556
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
High
CVE-2026-54763
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 6, 2026
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
CVE-2026-67309
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
High
CVE-2026-71327
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 6, 2026
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
High
CVE-2026-71324
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
High
CVE-2026-59733
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
High
CVE-2026-71312
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
High
CVE-2026-54572
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Incomplete path validation allows backend root escape in serve restic
High
CVE-2026-71309
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
High
GHSA-7qf5-7ppr-87v8
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 1, 2026
•
withdrawn
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
High
CVE-2026-67437
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
netfoil: Incorrect block responses could lead to localhost traffic
High
GHSA-xvg2-cgv6-6h7v
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API
High
CVE-2026-54693
was published
for
github.com/zitadel/zitadel
(Go)
Jul 29, 2026
openhole-server vulnerable to path traversal via URL-decoded request path
High
CVE-2026-54650
was published
for
github.com/bablilayoub/openhole
(Go)
Jul 28, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
High
CVE-2026-54719
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
High
CVE-2026-50567
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API