Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,475 advisories

Loading
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution High
CVE-2026-50163 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
anvanster Credited to anvanster and onelapahead onelapahead onelapahead
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward Moderate
CVE-2026-45045 was published for github.com/gofiber/fiber/v2 (Go) Jul 2, 2026
TristanInSec Credited to TristanInSec, ReneWerner87, gaby, and 0x01code ReneWerner87 ReneWerner87
gaby gaby 0x01code 0x01code
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys Critical
CVE-2026-39832 was published for golang.org/x/crypto (Go) Jun 25, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses Critical
CVE-2026-39830 was published for golang.org/x/crypto (Go) Jun 25, 2026
Rancher vulnerable to command injection through unsanitized YAML parameter Critical
CVE-2026-44939 was published for github.com/rancher/rancher (Go) Jul 1, 2026
Ibonok Credited to Ibonok
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message Moderate
CVE-2026-54908 was published for github.com/pion/dtls/v3 (Go) Jul 31, 2026
Sean-Der Credited to Sean-Der and kajaaz kajaaz kajaaz
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
sigstore-go fails to check signature timestamps against a signing key's validity period Low
CVE-2026-54787 was published for github.com/sigstore/sigstore-go (Go) Jul 31, 2026
tnytown Credited to tnytown
sigstore-go has a multi-log threshold bypass via single compromised log Moderate
CVE-2026-49834 was published for github.com/sigstore/sigstore-go (Go) Jul 9, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure Moderate
CVE-2026-53551 was published for github.com/free5gc/ausf (Go) Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API Critical
CVE-2026-54725 was published for github.com/bank-vaults/vault-secrets-webhook (Go) Jul 31, 2026
0xVijay Credited to 0xVijay
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) Moderate
CVE-2026-65835 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
thientd Credited to thientd
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
Wings exposes node configuration secrets through egg configuration-file templating Critical
CVE-2026-52855 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
robertdrakedennis Credited to robertdrakedennis
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
Apache Answer vulnerable to Cross-site Scripting Moderate
CVE-2026-34033 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability Moderate
CVE-2026-34905 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability Moderate
CVE-2026-33582 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability Moderate
CVE-2026-34031 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability Moderate
CVE-2026-25699 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability Moderate
CVE-2026-25688 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check Moderate
CVE-2026-67438 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
Ayantaker Credited to Ayantaker
ProTip! Advisories are also available from the GraphQL API