GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,494
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,494 advisories
Filter by severity
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
CVE-2026-65602
was published
for
github.com/traefik/traefik/v3
(Go)
Aug 5, 2026
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
GHSA-7m3p-wc52-rmc6
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
CVE-2026-65601
was published
for
Traefik
(Go)
Aug 5, 2026
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
GHSA-6mxq-jr92-3h2r
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
rclone: Local Encoding Path Traversal
Moderate
CVE-2026-71313
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone archive extract allows S3 destination prefix escape via crafted archive paths
Moderate
CVE-2026-59732
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
High
CVE-2026-59733
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
High
CVE-2026-71312
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
Moderate
GHSA-h4mf-4v27-hggj
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
Moderate
CVE-2026-71311
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
Moderate
GHSA-8mxv-9xhp-86h4
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
Moderate
GHSA-8v25-v8p6-qf7v
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
Moderate
GHSA-3x6r-wxxg-53vv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
Moderate
CVE-2026-71310
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
High
CVE-2026-54572
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Incomplete path validation allows backend root escape in serve restic
High
CVE-2026-71309
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
Low
GHSA-945v-v9p3-v5xw
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
Low
GHSA-gwfq-86j8-7qhv
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
High
CVE-2026-50163
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
Moderate
CVE-2026-45045
was published
for
github.com/gofiber/fiber/v2
(Go)
Jul 2, 2026
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Critical
CVE-2026-39832
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Critical
CVE-2026-39830
was published
for
golang.org/x/crypto
(Go)
Jun 25, 2026
Rancher vulnerable to command injection through unsanitized YAML parameter
Critical
CVE-2026-44939
was published
for
github.com/rancher/rancher
(Go)
Jul 1, 2026
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API