Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,977 advisories

Loading
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile Moderate
CVE-2026-54637 was published for d7y.io/dragonfly/v2 (Go) Jul 6, 2026
tonghuaroot Credited to tonghuaroot and gaius-qi gaius-qi gaius-qi
SFTPGo has path confinement bypass in public browsable share partial ZIP download Moderate
CVE-2026-49244 was published for github.com/drakkan/sftpgo/v2 (Go) Jul 2, 2026
celinke97 Credited to celinke97
Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect Moderate
CVE-2026-50192 was published for github.com/kerberos-io/agent/machinery (Go) Jul 2, 2026
tonghuaroot Credited to tonghuaroot
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled Moderate
CVE-2026-50149 was published for github.com/projectcontour/contour (Go) Jul 2, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward Moderate
CVE-2026-45045 was published for github.com/gofiber/fiber/v2 (Go) Jul 2, 2026
TristanInSec Credited to TristanInSec, ReneWerner87, gaby, and 0x01code ReneWerner87 ReneWerner87
gaby gaby 0x01code 0x01code
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer Moderate
CVE-2026-44332 was published for github.com/gofiber/fiber/v3 (Go) Jul 2, 2026
TristanInSec Credited to TristanInSec, gaby, and ReneWerner87 gaby gaby
ReneWerner87 ReneWerner87
goshs: Share-link ?token=… redemption races past download limit Moderate
CVE-2026-50139 was published for goshs.de/goshs/v2 (Go) Jul 1, 2026
black-shadow-007 Credited to black-shadow-007
ORAS Go forwards registry credentials across registry redirects Moderate
GHSA-vh4v-2xq2-g5cg was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
mosskappa Credited to mosskappa
oras-go has file store write outside workingDir via symlink traversal Moderate
CVE-2026-50162 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
1seal Credited to 1seal
tonghuaroot Credited to tonghuaroot
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml Moderate
CVE-2026-44936 was published for github.com/rancher/fleet (Go) Jul 1, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts Moderate
GHSA-3ccm-4qq2-5wrp was published for github.com/edgelesssys/contrast (Go) Jul 1, 2026
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality Moderate
CVE-2026-49835 was published for github.com/sigstore/timestamp-authority (Go) Jun 30, 2026
Probo has an open redirect bypass via path normalization Moderate
CVE-2026-49820 was published for go.probo.inc/probo (Go) Jun 30, 2026
Fushuling Credited to Fushuling
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container Moderate
CVE-2026-50565 was published for github.com/fission/fission (Go) Jun 30, 2026
tonghuaroot Credited to tonghuaroot and sanketsudake sanketsudake sanketsudake
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API Moderate
GHSA-ww5p-j6cj-6mqq was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
sondt99 Credited to sondt99
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection Moderate
CVE-2026-53523 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
alcls01111 Credited to alcls01111
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS Moderate
CVE-2026-53522 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
alcls01111 Credited to alcls01111
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context Moderate
CVE-2026-53521 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
baradika Credited to baradika
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing Moderate
CVE-2026-53520 was published for github.com/nezhahq/nezha (Go) Jun 26, 2026
sondt99 Credited to sondt99
regclient may leak authentication credentials to external blob stores Moderate
CVE-2026-49349 was published for github.com/regclient/regclient (Go) Jun 26, 2026
GimmyDatBeeR Credited to GimmyDatBeeR and sudo-bmitch sudo-bmitch sudo-bmitch
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container Moderate
GHSA-rhq6-9rgh-v45c was published for github.com/pterodactyl/wings (Go) Jun 26, 2026
Vz0n Credited to Vz0n
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions Moderate
CVE-2026-48790 was published for github.com/tursodatabase/turso-cli (Go) Jun 26, 2026
Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint Moderate
CVE-2026-41262 was published for github.com/fleetdm/fleet/v4 (Go) Jun 26, 2026
offset Credited to offset
Apptainer has incorrect path matching for 'limit container paths' directive Moderate
CVE-2026-48785 was published for github.com/apptainer/apptainer (Go) Jun 26, 2026
dtrudg Credited to dtrudg
ProTip! Advisories are also available from the GraphQL API