GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
499 advisories
Filter by severity
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Critical
CVE-2026-52811
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
Critical
CVE-2026-52806
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Critical
GHSA-wfqx-gjrf-g28r
was published
for
github.com/crossplane/crossplane
(Go)
Jun 19, 2026
Tilt: Missing authentication on the network-exposed Tilt HUD server
Critical
CVE-2026-55884
was published
for
github.com/tilt-dev/tilt
(Go)
Jun 19, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
Critical
CVE-2026-11718
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 18, 2026
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
Critical
CVE-2026-11717
was published
for
github.com/googleapis/mcp-toolbox
(Go)
Jun 18, 2026
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Critical
CVE-2026-49980
was published
for
github.com/rclone/rclone
(Go)
Jun 16, 2026
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
Critical
CVE-2026-48031
was published
for
github.com/dhax/go-base
(Go)
Jun 10, 2026
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
Critical
CVE-2026-47724
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 8, 2026
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin
Critical
CVE-2026-47252
was published
for
github.com/julien040/anyquery/plugins/brave
(Go)
Jun 8, 2026
Casdoor doesn't verify that a JWT used for token exchange is still active
Critical
CVE-2026-9097
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Casdoor does not validate the AudienceRestriction element in SAML assertions
Critical
CVE-2026-9093
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Casdoor has an authentication bypass
Critical
CVE-2026-9090
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Casdoor SAML callback handler accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest
Critical
CVE-2026-9098
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
Critical
CVE-2026-9094
was published
for
github.com/casdoor/casdoor
(Go)
May 28, 2026
MCP Toolbox for Databases vulnerable to DNS rebinding attacks
Critical
CVE-2026-9739
was published
for
github.com/googleapis/mcp-toolbox
(Go)
May 28, 2026
KubeVirt has a Link Following vulnerability
Critical
CVE-2026-7374
was published
for
kubevirt.io/kubevirt
(Go)
May 26, 2026
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
Critical
CVE-2026-46716
was published
for
github.com/nezhahq/nezha
(Go)
May 23, 2026
FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
Critical
CVE-2026-48777
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
May 22, 2026
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
Critical
CVE-2026-46614
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
Critical
CVE-2026-46354
was published
for
github.com/coder/coder
(Go)
May 19, 2026
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
Critical
GHSA-g53w-w6mj-hrpp
was published
for
github.com/Kuadrant/mcp-gateway
(Go)
May 19, 2026
Kopia: RCE via SSH ProxyCommand Injection
Critical
CVE-2026-45695
was published
for
github.com/kopia/kopia
(Go)
May 19, 2026
ProTip!
Advisories are also available from the
GraphQL API