Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,977 advisories

Loading
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) Moderate
CVE-2026-58425 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads Moderate
CVE-2026-59763 was published for code.gitea.io/gitea (Go) Jul 21, 2026
kkkh1 Credited to kkkh1
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) Moderate
CVE-2026-58428 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
JebeenLee Credited to JebeenLee and alecclyde alecclyde alecclyde
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) Moderate
CVE-2026-62843 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope Moderate
CVE-2026-55668 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
DavidCarliez Credited to DavidCarliez, riodrwn, and hacdias riodrwn riodrwn
hacdias hacdias
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses Moderate
CVE-2026-54562 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 20, 2026
baradika Credited to baradika and riodrwn riodrwn riodrwn
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication Moderate
CVE-2026-54246 was published for github.com/zalando/skipper (Go) Jul 17, 2026
alcls01111 Credited to alcls01111
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS Moderate
CVE-2026-54247 was published for github.com/zalando/skipper (Go) Jul 17, 2026
alcls01111 Credited to alcls01111
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-52724 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container Moderate
CVE-2026-52832 was published for github.com/nuclio/nuclio (Go) Jul 16, 2026
j311yl0v3u Credited to j311yl0v3u and b0b0haha b0b0haha b0b0haha
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock Moderate
CVE-2026-53715 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header Moderate
CVE-2026-53717 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization Moderate
CVE-2026-53719 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit Moderate
CVE-2026-53716 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass Moderate
CVE-2026-53718 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-50166 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters Moderate
CVE-2026-54495 was published for github.com/open-feature/open-feature-operator (Go) Jul 15, 2026
0xVijay Credited to 0xVijay
safeurl is Missing IPv6 CIDR Ranges in Blocklist Moderate
CVE-2026-54452 was published for github.com/doyensec/safeurl (Go) Jul 15, 2026
tonghuaroot Credited to tonghuaroot
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens Moderate
CVE-2026-55513 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting Moderate
CVE-2026-55512 was published for github.com/forgekeep/nebula-mesh (Go) Jul 14, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
ProTip! Advisories are also available from the GraphQL API