GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,509 advisories
Filter by severity
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Moderate
GHSA-v6w6-358x-2433
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
High
GHSA-26gq-p25f-99cp
was published
for
github.com/fatedier/frp
(Go)
Jul 24, 2026
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Moderate
GHSA-c534-2w9c-x7fm
was published
for
github.com/zxh326/kite
(Go)
Jul 24, 2026
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Moderate
CVE-2026-62323
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Moderate
CVE-2026-57497
was published
for
github.com/quic-go/webtransport-go
(Go)
Jul 24, 2026
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
High
CVE-2026-55502
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Moderate
CVE-2026-55499
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Moderate
CVE-2026-55497
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
Moderate
CVE-2026-55496
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
Moderate
CVE-2026-55495
was published
for
github.com/cloudreve/Cloudreve/v3
(Go)
Jul 24, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
Moderate
GHSA-gcjh-h69q-9w9g
was published
for
github.com/google/cel-go
(Go)
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
Low
GHSA-464c-974j-9xm6
was published
for
@aws-cdk/aws-codebuild
(Go)
Jul 24, 2026
Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Moderate
GHSA-6mxq-jr92-3h2r
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Moderate
GHSA-7m3p-wc52-rmc6
was published
for
github.com/traefik/traefik
(Go)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
High
GHSA-rhg6-2vjh-j5qc
was published
for
github.com/traefik/traefik/v2
(Go)
Jul 22, 2026
•
withdrawn
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
High
GHSA-hrxh-6v49-42gf
was published
for
google.golang.org/grpc
(Go)
Jul 21, 2026
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
High
CVE-2026-20779
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Moderate
CVE-2026-58429
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Moderate
CVE-2026-59765
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Webhook Authorization Header Returned in Plaintext via API
Low
CVE-2026-58511
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Moderate
CVE-2026-57897
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
Moderate
CVE-2026-58510
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Public-only API token restriction is not enforced on team API routes
Moderate
CVE-2026-58431
was published
for
gitea.dev
(Go)
Jul 21, 2026
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
Moderate
CVE-2026-58427
was published
for
gitea.dev
(Go)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API