GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,475 advisories
Filter by severity
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
High
CVE-2026-50163
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
Moderate
CVE-2026-45045
was published
for
github.com/gofiber/fiber/v2
(Go)
Jul 2, 2026
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Critical
CVE-2026-39832
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Rancher vulnerable to command injection through unsanitized YAML parameter
Critical
CVE-2026-44939
was published
for
github.com/rancher/rancher
(Go)
Jul 1, 2026
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Moderate
CVE-2026-54908
was published
for
github.com/pion/dtls/v3
(Go)
Jul 31, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
sigstore-go fails to check signature timestamps against a signing key's validity period
Low
CVE-2026-54787
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 31, 2026
sigstore-go has a multi-log threshold bypass via single compromised log
Moderate
CVE-2026-49834
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 9, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Critical
CVE-2026-54725
was published
for
github.com/bank-vaults/vault-secrets-webhook
(Go)
Jul 31, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
High
CVE-2026-52856
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Wings exposes node configuration secrets through egg configuration-file templating
Critical
CVE-2026-52855
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Apache Answer vulnerable to Cross-site Scripting
Moderate
CVE-2026-34033
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2026-34905
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Moderate
CVE-2026-33582
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Moderate
CVE-2026-34031
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Moderate
CVE-2026-25699
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Moderate
CVE-2026-25688
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
Moderate
CVE-2026-67438
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API