GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,647 advisories
Filter by severity
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
High
CVE-2026-24451
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Two SSRF findings
High
CVE-2026-58314
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
High
CVE-2026-58436
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Visibility Manipulation via Git Push Options
High
CVE-2026-58437
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
High
CVE-2026-55987
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
High
CVE-2026-54481
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
High
CVE-2026-58424
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
High
CVE-2026-58423
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
High
CVE-2026-58421
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
High
CVE-2026-28740
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API
High
CVE-2026-56654
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
High
CVE-2026-58439
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
High
CVE-2026-57894
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
File Browser: Colliding username normalization gives two users the same home directory
High
CVE-2026-62685
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
High
CVE-2026-55667
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
High
CVE-2026-54560
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Jul 20, 2026
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
High
GHSA-8qqm-fp2q-v734
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
Gitea has insufficient permission checks for Composer package source links
High
CVE-2026-27771
was published
for
code.gitea.io/gitea
(Go)
Jul 17, 2026
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
High
CVE-2026-52833
was published
for
github.com/nuclio/nuclio
(Go)
Jul 16, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
High
CVE-2026-53714
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
High
CVE-2026-50285
was published
for
github.com/pomerium/pomerium
(Go)
Jul 15, 2026
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
High
CVE-2026-50274
was published
for
github.com/DataDog/dd-trace-go
(Go)
Jul 15, 2026
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
High
CVE-2026-61549
was published
for
github.com/woodpecker-ci/woodpecker
(Go)
Jul 14, 2026
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
High
GHSA-7rx3-5wx3-5v76
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API