GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,455 advisories
Filter by severity
netfoil: Incorrect block responses could lead to localhost traffic
High
GHSA-xvg2-cgv6-6h7v
was published
for
github.com/tinfoil-factory/netfoil
(Go)
Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution
Critical
CVE-2026-54680
was published
for
github.com/kube-logging/logging-operator
(Go)
Jul 29, 2026
ZITADEL Users Can Self-Verify Email/Phone via API
High
CVE-2026-54693
was published
for
github.com/zitadel/zitadel
(Go)
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Critical
CVE-2026-54735
was published
for
github.com/prebid/prebid-server
(Go)
Jul 29, 2026
goshs has ACL Bypass & Path Traversal
Moderate
CVE-2026-66064
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
openhole-server vulnerable to path traversal via URL-decoded request path
High
CVE-2026-54650
was published
for
github.com/bablilayoub/openhole
(Go)
Jul 28, 2026
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
High
CVE-2026-54638
was published
for
github.com/gotd/td
(Go)
Jul 28, 2026
goshs has a Path Traversal issue
Moderate
CVE-2026-66063
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Critical
CVE-2026-64863
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
High
CVE-2026-54719
was published
for
github.com/patrickhener/goshs
(Go)
Jul 28, 2026
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Critical
CVE-2026-62325
was published
for
github.com/patrickhener/goshs/v2
(Go)
Jul 28, 2026
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Moderate
CVE-2026-49446
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Low
CVE-2026-50568
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
High
CVE-2026-50567
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Moderate
CVE-2026-50569
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
High
CVE-2026-50570
was published
for
github.com/fission/fission
(Go)
Jul 28, 2026
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Moderate
CVE-2026-54332
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
Moderate
CVE-2026-54345
was published
for
github.com/gopacket/gopacket
(Go)
Jul 28, 2026
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
High
CVE-2026-54593
was published
for
github.com/pterodactyl/wings
(Composer)
Jul 28, 2026
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
High
CVE-2026-47427
was published
for
github.com/github/github-mcp-server
(Go)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
High
GHSA-6vch-q96h-7gc3
was published
for
go.etcd.io/etcd/v3
(Go)
Jul 24, 2026
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Moderate
GHSA-jpcw-4wr7-c3vq
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API