Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

357 advisories

Loading
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing Low
CVE-2026-71326 was published for github.com/traefik/traefik/v3 (Go) Aug 6, 2026
hussst Credited to hussst
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect Low
GHSA-gx4c-2hqx-cw2r was published for github.com/rclone/rclone (Go) Aug 5, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and ncw ncw ncw
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote Low
GHSA-945v-v9p3-v5xw was published for github.com/rclone/rclone (Go) Aug 5, 2026
vnth4nhnt Credited to vnth4nhnt and ncw ncw ncw
rclone: Verbose Stack Trace Disclosure in RC API Error Responses Low
GHSA-gwfq-86j8-7qhv was published for github.com/rclone/rclone (Go) Aug 5, 2026
SnailSploit Credited to SnailSploit and ncw ncw ncw
sigstore-go fails to check signature timestamps against a signing key's validity period Low
CVE-2026-54787 was published for github.com/sigstore/sigstore-go (Go) Jul 31, 2026
tnytown Credited to tnytown
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape Low
CVE-2026-50568 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API Low
CVE-2026-58511 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Gitea: Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service Low
CVE-2026-55984 was published for code.gitea.io/gitea (Go) Jul 21, 2026
martijnperdaan52 Credited to martijnperdaan52
Gitea: Private Repository Metadata Remains Accessible After Access Revocation Low
CVE-2026-58434 was published for code.gitea.io/gitea (Go) Jul 21, 2026
ybsun0215 Credited to ybsun0215
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim Low
CVE-2026-23603 was published for code.gitea.io/gitea (Go) Jul 21, 2026
alimezar Credited to alimezar, Vext-Labs, theluckystrike, prakhar0x01, AnuragBathani, and khoadb175 Vext-Labs Vext-Labs
theluckystrike theluckystrike prakhar0x01 prakhar0x01 AnuragBathani AnuragBathani khoadb175 khoadb175
File Browser: Share API exposes the password hash and bypass token Low
CVE-2026-62684 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code Low
GHSA-rjwr-m7qx-3fjr was published for github.com/oapi-codegen/oapi-codegen/v2 (Go) Jul 17, 2026
quart27219 Credited to quart27219 and kimdu0 kimdu0 kimdu0
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) Low
CVE-2026-58196 was published for github.com/stacklok/toolhive (Go) Jul 15, 2026
bIackr0se Credited to bIackr0se, jhrozek, JAORMX, ChrisJBurns, and rdimitrov jhrozek jhrozek
JAORMX JAORMX ChrisJBurns ChrisJBurns rdimitrov rdimitrov
tonghuaroot Credited to tonghuaroot, rdimitrov, and JAORMX rdimitrov rdimitrov
JAORMX JAORMX
netfoil: Attacker controlled data written to logs Low
GHSA-7856-g3gv-9wq8 was published for github.com/tinfoil-factory/netfoil (Go) Jul 7, 2026
stigtsp Credited to stigtsp
netfoil has a resource leak in LRU cache Low
GHSA-3g4q-2f67-2gvh was published for github.com/tinfoil-factory/netfoil (Go) Jul 7, 2026
stigtsp Credited to stigtsp
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth Low
CVE-2026-49254 was published for d7y.io/dragonfly/v2 (Go) Jul 2, 2026
tonghuaroot Credited to tonghuaroot
SFTPGo has stored XSS via inline parameter on public shares and user file download Low
CVE-2026-49245 was published for github.com/drakkan/sftpgo/v2 (Go) Jul 2, 2026
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens Low
CVE-2026-48978 was published for oras.land/oras-go (Go) Jul 1, 2026
1seal Credited to 1seal
Concourse login flow has an open redirect issue Low
CVE-2026-49826 was published for github.com/concourse/concourse (Go) Jul 1, 2026
Fushuling Credited to Fushuling and RacerZ-fighting RacerZ-fighting RacerZ-fighting
offset Credited to offset
Authelia has an Edge Case Access Control Rule Mismatch Low
CVE-2026-48794 was published for github.com/authelia/authelia/v4 (Go) Jun 26, 2026
j0hndo Credited to j0hndo, james-d-elliott, Crowley723, and nightah james-d-elliott james-d-elliott
Crowley723 Crowley723 nightah nightah
ProTip! Advisories are also available from the GraphQL API