GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
73 advisories
Filter by severity
UEFI Firmware Parser has a heap out-of-bounds write in tiano decompressor ReadCLen
Critical
CVE-2026-54334
was published
for
uefi-firmware
(pip)
Apr 16, 2026
UEFI Firmware Parser has a stack out-of-bounds write in tiano decompressor MakeTable
Critical
CVE-2026-54333
was published
for
uefi-firmware
(pip)
Apr 16, 2026
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
High
CVE-2026-40868
was published
for
github.com/kyverno/kyverno
(Go)
Apr 14, 2026
nimiq-consensus panics via RequestMacroChain micro-block locator
Moderate
CVE-2026-34069
was published
for
nimiq-consensus
(Rust)
Apr 13, 2026
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
Low
CVE-2026-40097
was published
for
github.com/smallstep/certificates
(Go)
Apr 10, 2026
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Moderate
CVE-2026-35206
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2026
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
Moderate
CVE-2026-39882
was published
for
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
(Go)
Apr 8, 2026
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
High
CVE-2026-29181
was published
for
go.opentelemetry.io/otel
(Go)
Apr 7, 2026
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
High
CVE-2026-35172
was published
for
github.com/distribution/distribution
(Go)
Apr 6, 2026
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
High
CVE-2026-33540
was published
for
github.com/distribution/distribution
(Go)
Apr 6, 2026
cryptography has incomplete DNS name constraint enforcement on peer names
Low
CVE-2026-34073
was published
for
cryptography
(pip)
Mar 27, 2026
Moby has AuthZ plugin bypass when provided oversized request bodies
High
CVE-2026-34040
was published
for
github.com/moby/moby
(Go)
Mar 27, 2026
BuildKit's Malicious frontend can cause file escape outside of storage root
High
CVE-2026-33747
was published
for
github.com/moby/buildkit
(Go)
Mar 26, 2026
webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
Moderate
GHSA-pwjx-qhcg-rvj4
was published
for
rustls-webpki
(Rust)
Mar 20, 2026
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
Critical
CVE-2026-33211
was published
for
github.com/tektoncd/pipeline
(Go)
Mar 18, 2026
Duplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
High
GHSA-wmxr-6j5f-838p
was published
for
org.keycloak:keycloak-saml-adapter-core
(Maven)
Mar 18, 2026
•
withdrawn
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
Moderate
CVE-2026-33022
was published
for
github.com/tektoncd/pipeline
(Go)
Mar 17, 2026
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Moderate
CVE-2026-29777
was published
for
github.com/traefik/traefik
(Go)
Mar 11, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required)
High
CVE-2026-31801
was published
for
zotregistry.dev/zot
(Go)
Mar 10, 2026
traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)
High
CVE-2026-29054
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)
High
CVE-2026-26999
was published
for
github.com/traefik/traefik/v2
(Go)
Mar 4, 2026
OpenClaw's sandbox skill mirroring path traversal vulnerability could write outside the sandbox workspace
Moderate
CVE-2026-28457
was published
for
openclaw
(npm)
Mar 2, 2026
`melange update-cache` has unbounded HTTP download that can exhaust disk in CI
Moderate
CVE-2026-29049
was published
for
chainguard.dev/melange
(Go)
Mar 2, 2026
malcontent: Error-path cleanup gap can leak scanners and fds and degrade availability
Moderate
GHSA-54p8-x2m9-c593
was published
for
github.com/chainguard-dev/malcontent
(Go)
Mar 2, 2026
kaniko has tar archive path traversal in its build context extraction, allowing file writes outside destination directories
High
CVE-2026-28406
was published
for
github.com/chainguard-dev/kaniko
(Go)
Mar 1, 2026
ProTip!
Advisories are also available from the
GraphQL API