Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

46 advisories

Loading
kodareef5 Credited to kodareef5
kodareef5 Credited to kodareef5
kodareef5 Credited to kodareef5
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware Moderate
CVE-2026-41263 was published for github.com/traefik/traefik (Go) Apr 24, 2026
kodareef5 Credited to kodareef5
phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals() Low
CVE-2026-40194 was published for phpseclib/phpseclib (Composer) Apr 10, 2026
kodareef5 Credited to kodareef5
Cillium exposes sensitive information included in the cilium-bugtool debug archive High
CVE-2026-41520 was published for github.com/cilium/cilium (Go) Apr 25, 2026
tklauser Credited to tklauser and kodareef5 kodareef5 kodareef5
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering Critical
CVE-2026-41050 was published for github.com/rancher/fleet (Go) May 7, 2026
kodareef5 Credited to kodareef5
Kata Container has CopyFile Policy Subversion via Symlinks High
CVE-2026-41326 was published for github.com/kata-containers/kata-containers (Go) May 4, 2026
fitzthum Credited to fitzthum, calonso-nv, fikriwahab, burgerdev, danmihai1, jojimt, fidencio, and kodareef5 calonso-nv calonso-nv
fikriwahab fikriwahab burgerdev burgerdev danmihai1 danmihai1 jojimt jojimt fidencio fidencio kodareef5 kodareef5
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL High
CVE-2026-40161 was published for github.com/tektoncd/pipeline (Go) Apr 21, 2026
kodareef5 Credited to kodareef5, vdemeester, stenzopolis1986-art, and waveywaves vdemeester vdemeester
stenzopolis1986-art stenzopolis1986-art waveywaves waveywaves
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check Moderate
CVE-2026-40923 was published for github.com/tektoncd/pipeline (Go) Apr 21, 2026
kodareef5 Credited to kodareef5, vdemeester, aThorp96, and waveywaves vdemeester vdemeester
aThorp96 aThorp96 waveywaves waveywaves
tuf has platform-dependent delegation path matching Moderate
GHSA-qp9x-wp8f-qgjj was published for tuf (pip) May 28, 2026
kodareef5 Credited to kodareef5
go-git: Malformed Git object data may cause panics or resource exhaustion Moderate
GHSA-w5pp-99ch-qj29 was published for github.com/go-git/go-git/v5 (Go) May 29, 2026
hiddeco Credited to hiddeco, N0zoM1z0, AyushParkara, and kodareef5 N0zoM1z0 N0zoM1z0
AyushParkara AyushParkara kodareef5 kodareef5
BentoML: Command Injection in cloud deployment setup script High
CVE-2026-35043 was published for bentoml (pip) Apr 3, 2026
kodareef5 Credited to kodareef5
opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication Moderate
CVE-2026-55701 was published for github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver (Go) Jun 18, 2026
kodareef5 Credited to kodareef5
Contour has Lua code injection via Cookie Path Rewrite Policy High
CVE-2026-41246 was published for github.com/projectcontour/contour (Go) Apr 24, 2026
b0b0haha Credited to b0b0haha and kodareef5 kodareef5 kodareef5
kodareef5 Credited to kodareef5, grvijayan, IAM-marco, livio-a, cipher-creator, and N008x grvijayan grvijayan
IAM-marco IAM-marco livio-a livio-a cipher-creator cipher-creator N008x N008x
Composer has a command injection via malicious perforce reference High
CVE-2026-40261 was published for composer/composer (Composer) Apr 14, 2026
kodareef5 Credited to kodareef5
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE High
CVE-2026-40938 was published for github.com/tektoncd/pipeline (Go) Apr 21, 2026
offset Credited to offset, vdemeester, kodareef5, and waveywaves vdemeester vdemeester
kodareef5 kodareef5 waveywaves waveywaves
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
kodareef5 Credited to kodareef5
go-git: Worktree operations may follow symlinks High
CVE-2026-71556 was published for github.com/go-git/go-git/v5 (Go) Aug 7, 2026
kodareef5 Credited to kodareef5 and HughLewis20 HughLewis20 HughLewis20
ProTip! Advisories are also available from the GraphQL API