GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,475 advisories
Filter by severity
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
Critical
CVE-2026-20896
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
Critical
CVE-2026-22874
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
Moderate
GHSA-rjvx-x5h2-6px5
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API
High
CVE-2026-56654
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
High
CVE-2026-56755
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Moderate
CVE-2026-58507
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
Moderate
CVE-2026-57886
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
Low
CVE-2026-23603
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
Moderate
CVE-2026-58425
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
Moderate
CVE-2026-59763
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: draft release attachment disclosure via missing web authorization
Moderate
CVE-2026-58432
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Moderate
CVE-2026-58428
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
Moderate
CVE-2026-56443
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
High
CVE-2026-58439
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
Moderate
CVE-2026-59766
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
Moderate
CVE-2026-58440
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
High
CVE-2026-57894
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
File Browser: Colliding username normalization gives two users the same home directory
High
CVE-2026-62685
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Share API exposes the password hash and bypass token
Low
CVE-2026-62684
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
Moderate
CVE-2026-55668
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
High
CVE-2026-55667
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Moderate
CVE-2026-54562
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 20, 2026
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
High
CVE-2026-54560
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API