GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
499 advisories
Filter by severity
S3-Proxy has Security Issues in its Resource Path Matching Implementation
Critical
CVE-2026-42882
was published
for
github.com/oxyno-zeta/s3-proxy
(Go)
May 5, 2026
Pelican Web UI Affected by a Privilege Escalation Attack
Critical
CVE-2026-42571
was published
for
github.com/pelicanplatform/pelican
(Go)
May 4, 2026
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
Critical
CVE-2026-42560
was published
for
github.com/go-pkgz/auth
(Go)
Apr 30, 2026
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
Critical
CVE-2026-40281
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
Netmaker does not verify JWT signatures for host tokens
Critical
CVE-2026-38651
was published
for
github.com/gravitl/netmaker
(Go)
Apr 28, 2026
Note Mark: OIDC-registered users authenticated by submitting password "null"
Critical
CVE-2026-41571
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 25, 2026
go-zserio has Unbounded Memory Allocation for All Platforms
Critical
GHSA-xhj4-g6w8-2xjw
was published
for
github.com/woven-planet/go-zserio
(Go)
Apr 24, 2026
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Critical
CVE-2026-41492
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Critical
CVE-2026-41328
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Critical
CVE-2026-41327
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 24, 2026
ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function
Critical
CVE-2026-39087
was published
for
heckel.io/ntfy/v2
(Go)
Apr 23, 2026
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
Critical
CVE-2026-42072
was published
for
github.com/orneryd/nornicdb
(Go)
Apr 22, 2026
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Critical
CVE-2026-41179
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
Critical
CVE-2026-41176
was published
for
github.com/rclone/rclone
(Go)
Apr 22, 2026
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
Critical
CVE-2026-41070
was published
for
github.com/jkroepke/openvpn-auth-oauth2
(Go)
Apr 22, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
Critical
CVE-2026-41589
was published
for
charm.land/wish/v2
(Go)
Apr 18, 2026
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
Critical
CVE-2026-41574
was published
for
github.com/nhost/nhost
(Go)
Apr 18, 2026
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Critical
CVE-2026-40173
was published
for
github.com/dgraph-io/dgraph
(Go)
Apr 16, 2026
Pyroscope Exposes Storage Secret
Critical
CVE-2025-41118
was published
for
github.com/grafana/pyroscope
(Go)
Apr 15, 2026
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
Critical
CVE-2026-40575
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 15, 2026
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token
Critical
CVE-2026-6290
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Apr 15, 2026
Oxia has an OIDC token audience validation bypass via SkipClientIDCheck
Critical
CVE-2026-40946
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
OAuth2 Proxy's Health Check User-Agent Matching Bypasses Authentication in auth_request Mode
Critical
CVE-2026-34457
was published
for
github.com/oauth2-proxy/oauth2-proxy
(Go)
Apr 14, 2026
goshs has an empty-username SFTP password authentication bypass
Critical
CVE-2026-40884
was published
for
github.com/patrickhener/goshs
(Go)
Apr 14, 2026
Daptin has Unauthenticated Path Traversal and Zip Slip
Critical
GHSA-9cp7-j3f8-p5jx
was published
for
github.com/daptin/daptin
(Go)
Apr 10, 2026
ProTip!
Advisories are also available from the
GraphQL API