Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,509 advisories

Loading
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode High
CVE-2026-54638 was published for github.com/gotd/td (Go) Jul 28, 2026
ayman148754-cloud Credited to ayman148754-cloud
goshs has a Path Traversal issue Moderate
CVE-2026-66063 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
arpitjain099 Credited to arpitjain099
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite Critical
CVE-2026-64863 was published for github.com/patrickhener/goshs (Go) Jul 28, 2026
anir0y Credited to anir0y
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) Critical
CVE-2026-62325 was published for github.com/patrickhener/goshs/v2 (Go) Jul 28, 2026
yukikamome316 Credited to yukikamome316
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel Moderate
CVE-2026-49446 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
Dredsen Credited to Dredsen
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape Low
CVE-2026-50568 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory High
CVE-2026-50567 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks Moderate
CVE-2026-50569 was published for github.com/fission/fission (Go) Jul 28, 2026
0xshdax Credited to 0xshdax and sanketsudake sanketsudake sanketsudake
Yanchon918s Credited to Yanchon918s and sanketsudake sanketsudake sanketsudake
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
tonghuaroot Credited to tonghuaroot and mosajjal mosajjal mosajjal
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler High
CVE-2026-47427 was published for github.com/github/github-mcp-server (Go) Jul 28, 2026
manthanghasadiya Credited to manthanghasadiya
kodareef5 Credited to kodareef5
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions High
CVE-2026-43983 was published for github.com/pocket-id/pocket-id/backend (Go) Jul 28, 2026
kodareef5 Credited to kodareef5
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline High
GHSA-6vch-q96h-7gc3 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
matiasinsaurralde Credited to matiasinsaurralde
etcd: Watch API authorization bypass via open-ended range requests High
GHSA-xg4h-6gfc-h4m8 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
Oh My Posh: Arbitrary command execution via template injection in the path segment High
GHSA-6xj8-qv9j-xcjq was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data Moderate
GHSA-fwjx-9p69-h25h was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
GHSA-86cx-wwf4-phq4 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
GHSA-95cv-r8x4-vh75 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
ProTip! Advisories are also available from the GraphQL API