GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,977 advisories
Filter by severity
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
Moderate
CVE-2026-54637
was published
for
d7y.io/dragonfly/v2
(Go)
Jul 6, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download
Moderate
CVE-2026-49244
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Jul 2, 2026
Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect
Moderate
CVE-2026-50192
was published
for
github.com/kerberos-io/agent/machinery
(Go)
Jul 2, 2026
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
Moderate
CVE-2026-50149
was published
for
github.com/projectcontour/contour
(Go)
Jul 2, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
Moderate
CVE-2026-45045
was published
for
github.com/gofiber/fiber/v2
(Go)
Jul 2, 2026
GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
Moderate
CVE-2026-44332
was published
for
github.com/gofiber/fiber/v3
(Go)
Jul 2, 2026
goshs: Share-link ?token=… redemption races past download limit
Moderate
CVE-2026-50139
was published
for
goshs.de/goshs/v2
(Go)
Jul 1, 2026
ORAS Go forwards registry credentials across registry redirects
Moderate
GHSA-vh4v-2xq2-g5cg
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
oras-go has file store write outside workingDir via symlink traversal
Moderate
CVE-2026-50162
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Moderate
CVE-2026-48824
was published
for
github.com/axllent/mailpit
(Go)
Jul 1, 2026
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
Moderate
CVE-2026-44936
was published
for
github.com/rancher/fleet
(Go)
Jul 1, 2026
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
Moderate
GHSA-3ccm-4qq2-5wrp
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 1, 2026
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Moderate
CVE-2026-49835
was published
for
github.com/sigstore/timestamp-authority
(Go)
Jun 30, 2026
Probo has an open redirect bypass via path normalization
Moderate
CVE-2026-49820
was published
for
go.probo.inc/probo
(Go)
Jun 30, 2026
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Moderate
CVE-2026-50565
was published
for
github.com/fission/fission
(Go)
Jun 30, 2026
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
Moderate
GHSA-ww5p-j6cj-6mqq
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Moderate
CVE-2026-53523
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Moderate
CVE-2026-53522
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Moderate
CVE-2026-53521
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Moderate
CVE-2026-53520
was published
for
github.com/nezhahq/nezha
(Go)
Jun 26, 2026
regclient may leak authentication credentials to external blob stores
Moderate
CVE-2026-49349
was published
for
github.com/regclient/regclient
(Go)
Jun 26, 2026
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
Moderate
GHSA-rhq6-9rgh-v45c
was published
for
github.com/pterodactyl/wings
(Go)
Jun 26, 2026
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions
Moderate
CVE-2026-48790
was published
for
github.com/tursodatabase/turso-cli
(Go)
Jun 26, 2026
Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint
Moderate
CVE-2026-41262
was published
for
github.com/fleetdm/fleet/v4
(Go)
Jun 26, 2026
Apptainer has incorrect path matching for 'limit container paths' directive
Moderate
CVE-2026-48785
was published
for
github.com/apptainer/apptainer
(Go)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API