Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,002 advisories

Loading
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write Moderate
CVE-2026-63328 was published for github.com/aquasecurity/trivy (Go) Aug 18, 2026
fatihhcelik Credited to fatihhcelik
package pkcs12: Authentication bypass in Decode functions Moderate
GHSA-mpwr-8vm7-h73f was published for software.sslmate.com/src/go-pkcs12 (Go) Aug 17, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability Moderate
CVE-2026-55062 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
uniget CLI has an EDITOR Command Injection Moderate
CVE-2026-55061 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest Moderate
CVE-2026-45099 was published for github.com/gruntwork-io/terragrunt (Go) Aug 17, 2026
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass Moderate
CVE-2026-64865 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
lihui12388 Credited to lihui12388
New API: Admin can reset passkeys for same-level or higher-privileged users Moderate
CVE-2026-64866 was published for github.com/QuantumNous/new-api (Go) Aug 17, 2026
Mi0uno Credited to Mi0uno
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter Moderate
CVE-2026-53658 was published for github.com/hyperledger/fabric-ca (Go) Aug 14, 2026
brodmart Credited to brodmart and bestbeforetoday bestbeforetoday bestbeforetoday
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint Moderate
CVE-2026-48786 was published for github.com/fleetdm/fleet/v4 (Go) Aug 12, 2026
go-git: Malicious reference names may modify files outside the reference storage Moderate
CVE-2026-71557 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
Saku0512 Credited to Saku0512
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port Moderate
CVE-2026-54765 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
gooood4u Credited to gooood4u
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Moderate
CVE-2026-71325 was published for github.com/traefik/traefik (Go) Aug 6, 2026
ttzero25 Credited to ttzero25
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Moderate
CVE-2026-54764 was published for github.com/traefik/traefik (Go) Aug 6, 2026
Pig-Tail Credited to Pig-Tail
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
CVE-2026-65602 was published for github.com/traefik/traefik/v3 (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd and james-yusuke james-yusuke james-yusuke
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
CVE-2026-65601 was published for Traefik (Go) Aug 5, 2026
CuB3y0nd Credited to CuB3y0nd
rclone: Local Encoding Path Traversal Moderate
CVE-2026-71313 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone archive extract allows S3 destination prefix escape via crafted archive paths Moderate
CVE-2026-59732 was published for github.com/rclone/rclone (Go) Aug 5, 2026
Dangel165 Credited to Dangel165 and ncw ncw ncw
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect Moderate
GHSA-h4mf-4v27-hggj was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines Moderate
CVE-2026-71311 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys Moderate
GHSA-8mxv-9xhp-86h4 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: Path traversal in serve s3 allows reading and overwriting root-level files Moderate
GHSA-8v25-v8p6-qf7v was published for github.com/rclone/rclone (Go) Aug 5, 2026
Dangel165 Credited to Dangel165 and ncw ncw ncw
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic Moderate
GHSA-3x6r-wxxg-53vv was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory Moderate
CVE-2026-71310 was published for github.com/rclone/rclone (Go) Aug 5, 2026
cyberlanc3r Credited to cyberlanc3r and ncw ncw ncw
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message Moderate
CVE-2026-54908 was published for github.com/pion/dtls/v3 (Go) Jul 31, 2026
Sean-Der Credited to Sean-Der and kajaaz kajaaz kajaaz
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
ProTip! Advisories are also available from the GraphQL API