GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,977 advisories
Filter by severity
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Moderate
CVE-2026-58425
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Moderate
CVE-2026-59763
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Moderate
CVE-2026-58428
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Moderate
CVE-2026-56443
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Moderate
CVE-2026-59766
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Moderate
CVE-2026-58440
was published
for
gitea.dev
(Go)
Jul 21, 2026
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
Moderate
CVE-2026-55668
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Moderate
CVE-2026-54562
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 20, 2026
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication
Moderate
CVE-2026-54246
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS
Moderate
CVE-2026-54247
was published
for
github.com/zalando/skipper
(Go)
Jul 17, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-52724
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container
Moderate
CVE-2026-52832
was published
for
github.com/nuclio/nuclio
(Go)
Jul 16, 2026
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Moderate
CVE-2026-53715
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Moderate
CVE-2026-53717
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Moderate
CVE-2026-53719
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Moderate
CVE-2026-53716
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Moderate
CVE-2026-53718
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured
Moderate
CVE-2026-50166
was published
for
github.com/kumahq/kuma
(Go)
Jul 16, 2026
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters
Moderate
CVE-2026-54495
was published
for
github.com/open-feature/open-feature-operator
(Go)
Jul 15, 2026
safeurl is Missing IPv6 CIDR Ranges in Blocklist
Moderate
CVE-2026-54452
was published
for
github.com/doyensec/safeurl
(Go)
Jul 15, 2026
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens
Moderate
CVE-2026-55513
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting
Moderate
CVE-2026-55512
was published
for
github.com/forgekeep/nebula-mesh
(Go)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API