Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

515 advisories

Loading
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints Critical
CVE-2026-55068 was published for github.com/free5gc/free5gc (Go) Aug 28, 2026
980448499-mm Credited to 980448499-mm
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) Critical
CVE-2026-54755 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
nickgs1337 Credited to nickgs1337
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) Critical
CVE-2026-54754 was published for github.com/klever-io/klever-go (Go) Aug 28, 2026
fbsobreira Credited to fbsobreira
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import Critical
CVE-2026-54061 was published for github.com/dgraph-io/dgraph/v25 (Go) Aug 20, 2026
u-ktdi Credited to u-ktdi
New API: Integer overflow in quota billing yields negative charges (self-crediting) Critical
CVE-2026-71479 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388 and Calcium-Ion Calcium-Ion Calcium-Ion
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation Critical
CVE-2026-64859 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
August829 Credited to August829
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Critical
CVE-2026-73080 was published for github.com/seaweedfs/seaweedfs (Go) Aug 11, 2026
KadirArslan Credited to KadirArslan
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware Critical
CVE-2026-65600 was published for github.com/traefik/traefik (Go) Aug 6, 2026
C-h4ck-0 Credited to C-h4ck-0
0xVijay Credited to 0xVijay
Wings exposes node configuration secrets through egg configuration-file templating Critical
CVE-2026-52855 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
robertdrakedennis Credited to robertdrakedennis
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite Critical
CVE-2026-64863 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) Critical
CVE-2026-62325 was published for github.com/patrickhener/goshs/v2 (Go) Jul 28, 2026
yukikamome316 Credited to yukikamome316
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Gitea: Public-only repository tokens can update private PR head branches Critical
CVE-2026-58443 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ohxorud-dev Credited to ohxorud-dev and bircni bircni bircni
kamil-sawicki Credited to kamil-sawicki
rz1027 Credited to rz1027
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter Critical
CVE-2026-22874 was published for code.gitea.io/gitea (Go) Jul 21, 2026
JLLeitschuh Credited to JLLeitschuh and M8seven M8seven M8seven
Gitea Remember-Me Token Theft Not Invalidating Attacker Session Critical
CVE-2026-56750 was published for code.gitea.io/gitea (Go) Jul 21, 2026
AdamKorcz Credited to AdamKorcz
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure Critical
CVE-2026-53713 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
rudrakhp Credited to rudrakhp and dashingDragon dashingDragon dashingDragon
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode Critical
CVE-2026-50006 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation Critical
GHSA-g936-7jqj-mwv8 was published for github.com/almeidapaulopt/tsdproxy (Go) Jul 10, 2026
therawdev Credited to therawdev
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content Critical
CVE-2026-50551 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
Yunkaiwjs Credited to Yunkaiwjs
ProTip! Advisories are also available from the GraphQL API