GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
515 advisories
Filter by severity
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Critical
CVE-2026-55068
was published
for
github.com/free5gc/free5gc
(Go)
Aug 28, 2026
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
Critical
CVE-2026-54755
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Critical
CVE-2026-54754
was published
for
github.com/klever-io/klever-go
(Go)
Aug 28, 2026
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Critical
CVE-2026-54523
was published
for
github.com/kyverno/kyverno
(Go)
Aug 26, 2026
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Critical
CVE-2026-54061
was published
for
github.com/dgraph-io/dgraph/v25
(Go)
Aug 20, 2026
New API: Integer overflow in quota billing yields negative charges (self-crediting)
Critical
CVE-2026-71479
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Critical
CVE-2026-64859
was published
for
github.com/QuantumNous/new-api
(Go)
Aug 17, 2026
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
Critical
CVE-2026-73080
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 11, 2026
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Critical
CVE-2026-65600
was published
for
github.com/traefik/traefik
(Go)
Aug 6, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
Wings exposes node configuration secrets through egg configuration-file templating
Critical
CVE-2026-52855
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Critical
CVE-2026-62325
was published
for
github.com/patrickhener/goshs/v2
(Go)
Jul 28, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Gitea: Public-only repository tokens can update private PR head branches
Critical
CVE-2026-58443
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Critical
CVE-2026-58426
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
Critical
CVE-2026-20896
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
Critical
CVE-2026-22874
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Critical
CVE-2026-53713
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
Critical
GHSA-g936-7jqj-mwv8
was published
for
github.com/almeidapaulopt/tsdproxy
(Go)
Jul 10, 2026
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
Critical
CVE-2026-50551
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API