Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,647 advisories

Loading
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution High
CVE-2026-50163 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
anvanster Credited to anvanster and onelapahead onelapahead onelapahead
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files High
CVE-2026-54910 was published for github.com/gtsteffaniak/filebrowser/backend (Go) Jul 31, 2026
je-lv Credited to je-lv
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) High
CVE-2026-67437 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
knight-yagami Credited to knight-yagami
williammartin Credited to williammartin, BagToad, kommendorkapten, babakks, and nophlyzone BagToad BagToad
kommendorkapten kommendorkapten babakks babakks nophlyzone nophlyzone
netfoil: Incorrect block responses could lead to localhost traffic High
GHSA-xvg2-cgv6-6h7v was published for github.com/tinfoil-factory/netfoil (Go) Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API High
CVE-2026-54693 was published for github.com/zitadel/zitadel (Go) Jul 29, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
openhole-server vulnerable to path traversal via URL-decoded request path High
CVE-2026-54650 was published for github.com/bablilayoub/openhole (Go) Jul 28, 2026
MrSmiiith Credited to MrSmiiith
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) High
CVE-2026-54719 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
anir0y Credited to anir0y
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory High
CVE-2026-50567 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Yanchon918s Credited to Yanchon918s and sanketsudake sanketsudake sanketsudake
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler High
CVE-2026-47427 was published for github.com/github/github-mcp-server (Go) Jul 28, 2026
manthanghasadiya Credited to manthanghasadiya
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
GHSA-6vch-q96h-7gc3 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
etcd: Watch API authorization bypass via open-ended range requests High
GHSA-xg4h-6gfc-h4m8 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
Oh My Posh: Arbitrary command execution via template injection in the path segment High
GHSA-6xj8-qv9j-xcjq was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
GHSA-95cv-r8x4-vh75 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
GHSA-26gq-p25f-99cp was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials High
CVE-2026-55502 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` High
CVE-2026-52845 was published for github.com/caddyserver/caddy (Go) Jun 16, 2026
Vincent550102 Credited to Vincent550102 and dunglas dunglas dunglas
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High
GHSA-hrxh-6v49-42gf was published for google.golang.org/grpc (Go) Jul 21, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface High
CVE-2026-20779 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Kript0r3x Credited to Kript0r3x
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts High
CVE-2026-58422 was published for code.gitea.io/gitea (Go) Jul 21, 2026
chndlrx Credited to chndlrx
ProTip! Advisories are also available from the GraphQL API