GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,977 advisories
Filter by severity
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
Moderate
CVE-2026-45045
was published
for
github.com/gofiber/fiber/v2
(Go)
Jul 2, 2026
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Moderate
CVE-2026-54908
was published
for
github.com/pion/dtls/v3
(Go)
Jul 31, 2026
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Moderate
CVE-2026-54909
was published
for
github.com/pion/stun
(Go)
Jul 31, 2026
sigstore-go has a multi-log threshold bypass via single compromised log
Moderate
CVE-2026-49834
was published
for
github.com/sigstore/sigstore-go
(Go)
Jul 9, 2026
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Moderate
CVE-2026-53551
was published
for
github.com/free5gc/ausf
(Go)
Jul 31, 2026
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Moderate
CVE-2026-65835
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Moderate
CVE-2026-65834
was published
for
github.com/projectcapsule/capsule
(Go)
Jul 31, 2026
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Moderate
CVE-2026-52857
was published
for
github.com/pterodactyl/wings
(Go)
Jul 31, 2026
Apache Answer vulnerable to Cross-site Scripting
Moderate
CVE-2026-34033
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2026-34905
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Moderate
CVE-2026-33582
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Moderate
CVE-2026-34031
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Moderate
CVE-2026-25699
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Moderate
CVE-2026-25688
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
Moderate
CVE-2026-67438
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
Moderate
CVE-2026-67439
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
Moderate
CVE-2026-39835
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
goshs has ACL Bypass & Path Traversal
Moderate
CVE-2026-66064
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs has a Path Traversal issue
Moderate
CVE-2026-66063
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Moderate
CVE-2026-50569
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Moderate
CVE-2026-54332
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API