Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,977 advisories

Loading
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward Moderate
CVE-2026-45045 was published for github.com/gofiber/fiber/v2 (Go) Jul 2, 2026
TristanInSec Credited to TristanInSec, ReneWerner87, gaby, and 0x01code ReneWerner87 ReneWerner87
gaby gaby 0x01code 0x01code
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message Moderate
CVE-2026-54908 was published for github.com/pion/dtls/v3 (Go) Jul 31, 2026
Sean-Der Credited to Sean-Der and kajaaz kajaaz kajaaz
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute Moderate
CVE-2026-54909 was published for github.com/pion/stun (Go) Jul 31, 2026
kajaaz Credited to kajaaz and Sean-Der Sean-Der Sean-Der
sigstore-go has a multi-log threshold bypass via single compromised log Moderate
CVE-2026-49834 was published for github.com/sigstore/sigstore-go (Go) Jul 9, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure Moderate
CVE-2026-53551 was published for github.com/free5gc/ausf (Go) Jul 31, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) Moderate
CVE-2026-65835 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
thientd Credited to thientd
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests Moderate
CVE-2026-65834 was published for github.com/projectcapsule/capsule (Go) Jul 31, 2026
PhucQuan Credited to PhucQuan
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM Moderate
CVE-2026-52857 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
WilliamVenner Credited to WilliamVenner
Apache Answer vulnerable to Cross-site Scripting Moderate
CVE-2026-34033 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability Moderate
CVE-2026-34905 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability Moderate
CVE-2026-33582 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability Moderate
CVE-2026-34031 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability Moderate
CVE-2026-25699 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability Moderate
CVE-2026-25688 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check Moderate
CVE-2026-67438 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
Ayantaker Credited to Ayantaker
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output Moderate
CVE-2026-67439 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
offset Credited to offset
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow Moderate
CVE-2026-39835 was published for golang.org/x/crypto (Go) Jun 25, 2026
goshs has ACL Bypass & Path Traversal Moderate
CVE-2026-66064 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
goshs has a Path Traversal issue Moderate
CVE-2026-66063 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks Moderate
CVE-2026-50569 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS Moderate
CVE-2026-54332 was published for github.com/gopacket/gopacket (Go) Jul 28, 2026
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) Moderate
CVE-2026-54345 was published for github.com/gopacket/gopacket (Go) Jul 28, 2026
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method Moderate
GHSA-hp74-gm6m-2qm5 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
ProTip! Advisories are also available from the GraphQL API