Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,509 advisories

Loading
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
GHSA-26gq-p25f-99cp was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources Moderate
GHSA-c534-2w9c-x7fm was published for github.com/zxh326/kite (Go) Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored Moderate
CVE-2026-62323 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules Moderate
CVE-2026-57497 was published for github.com/quic-go/webtransport-go (Go) Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials High
CVE-2026-55502 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Moderate
CVE-2026-55497 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
riodrwn Credited to riodrwn
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account Moderate
CVE-2026-55495 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
riodrwn Credited to riodrwn
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag Moderate
GHSA-gcjh-h69q-9w9g was published for github.com/google/cel-go (Go) Jul 24, 2026
anaximand3r Credited to anaximand3r and doyensec-mohamed doyensec-mohamed doyensec-mohamed
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion Low
GHSA-464c-974j-9xm6 was published for @aws-cdk/aws-codebuild (Go) Jul 24, 2026
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Moderate
GHSA-6mxq-jr92-3h2r was published for github.com/traefik/traefik (Go) Jul 22, 2026 withdrawn
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Moderate
GHSA-7m3p-wc52-rmc6 was published for github.com/traefik/traefik (Go) Jul 22, 2026 withdrawn
Duplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware High
GHSA-rhg6-2vjh-j5qc was published for github.com/traefik/traefik/v2 (Go) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities High
GHSA-hrxh-6v49-42gf was published for google.golang.org/grpc (Go) Jul 21, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface High
CVE-2026-20779 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Kript0r3x Credited to Kript0r3x
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints Moderate
CVE-2026-58429 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Pcat2003 Credited to Pcat2003
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata Moderate
CVE-2026-59765 was published for code.gitea.io/gitea (Go) Jul 21, 2026
tikket1 Credited to tikket1, Letian-aarch64, JebeenLee, JLLeitschuh, pick, and kdalal-vulncheck Letian-aarch64 Letian-aarch64
JebeenLee JebeenLee JLLeitschuh JLLeitschuh pick pick kdalal-vulncheck kdalal-vulncheck
Gitea: Webhook Authorization Header Returned in Plaintext via API Low
CVE-2026-58511 was published for code.gitea.io/gitea (Go) Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs Moderate
CVE-2026-57897 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: Public-only API token restriction is not enforced on team API routes Moderate
CVE-2026-58431 was published for gitea.dev (Go) Jul 21, 2026
rmb122 Credited to rmb122
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145 Moderate
CVE-2026-58427 was published for gitea.dev (Go) Jul 21, 2026
Razzlemouse Credited to Razzlemouse
ProTip! Advisories are also available from the GraphQL API