Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,455 advisories

Loading
netfoil: Incorrect block responses could lead to localhost traffic High
GHSA-xvg2-cgv6-6h7v was published for github.com/tinfoil-factory/netfoil (Go) Jul 29, 2026
Logging operator has Fluentd configuration injection that allows remote code execution Critical
CVE-2026-54680 was published for github.com/kube-logging/logging-operator (Go) Jul 29, 2026
hnts Credited to hnts
ZITADEL Users Can Self-Verify Email/Phone via API High
CVE-2026-54693 was published for github.com/zitadel/zitadel (Go) Jul 29, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
prebid-server's request forgery vulnerability allows for possible host environment data extraction Critical
CVE-2026-54735 was published for github.com/prebid/prebid-server (Go) Jul 29, 2026
goshs has ACL Bypass & Path Traversal Moderate
CVE-2026-66064 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
openhole-server vulnerable to path traversal via URL-decoded request path High
CVE-2026-54650 was published for github.com/bablilayoub/openhole (Go) Jul 28, 2026
MrSmiiith Credited to MrSmiiith
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
goshs has a Path Traversal issue Moderate
CVE-2026-66063 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite Critical
CVE-2026-64863 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
anir0y Credited to anir0y
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) Critical
CVE-2026-62325 was published for github.com/patrickhener/goshs/v2 (Go) Jul 28, 2026
yukikamome316 Credited to yukikamome316
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape Low
CVE-2026-50568 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory High
CVE-2026-50567 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks Moderate
CVE-2026-50569 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Yanchon918s Credited to Yanchon918s and sanketsudake sanketsudake sanketsudake
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler High
CVE-2026-47427 was published for github.com/github/github-mcp-server (Go) Jul 28, 2026
manthanghasadiya Credited to manthanghasadiya
kodareef5 Credited to kodareef5
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
GHSA-6vch-q96h-7gc3 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
matiasinsaurralde Credited to matiasinsaurralde
ProTip! Advisories are also available from the GraphQL API