GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
25 advisories
Filter by severity
go-git: Worktree operations may follow symlinks
High
CVE-2026-71556
was published
for
github.com/go-git/go-git/v5
(Go)
Aug 7, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
High
CVE-2026-55672
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
High
GHSA-mm2q-qcmx-gw4w
was published
for
rustfs
(Rust)
May 5, 2026
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
High
GHSA-x494-mj8g-cj27
was published
for
gix-pack
(Rust)
May 5, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
GHSA-p3hw-mv63-rf9w
was published
for
gix
(Rust)
May 5, 2026
Kata Container has CopyFile Policy Subversion via Symlinks
High
CVE-2026-41326
was published
for
github.com/kata-containers/kata-containers
(Go)
May 4, 2026
Cillium exposes sensitive information included in the cilium-bugtool debug archive
High
CVE-2026-41520
was published
for
github.com/cilium/cilium
(Go)
Apr 25, 2026
Contour has Lua code injection via Cookie Path Rewrite Policy
High
CVE-2026-41246
was published
for
github.com/projectcontour/contour
(Go)
Apr 24, 2026
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
High
CVE-2026-40937
was published
for
rustfs
(Rust)
Apr 22, 2026
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
High
CVE-2026-40938
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
High
CVE-2026-40161
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Statamic: Unsafe method invocation via query value resolution allows data destruction
High
CVE-2026-41175
was published
for
statamic/cms
(Composer)
Apr 16, 2026
Novu has SSRF via conditions filter webhook bypasses validateUrlSsrf() protection
High
GHSA-4x48-cgf9-q33f
was published
for
@novu/api
(npm)
Apr 14, 2026
Composer has a command injection via malicious perforce reference
High
CVE-2026-40261
was published
for
composer/composer
(Composer)
Apr 14, 2026
External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine
High
CVE-2026-34984
was published
for
github.com/external-secrets/external-secrets
(Go)
Apr 13, 2026
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
High
CVE-2026-40107
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 10, 2026
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
High
CVE-2026-39883
was published
for
go.opentelemetry.io/otel/sdk
(Go)
Apr 8, 2026
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
High
CVE-2026-35607
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
File Browser share links remain accessible after Share/Download permissions are revoked
High
CVE-2026-35604
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
High
GHSA-x3f4-v83f-7wp2
was published
for
github.com/authorizerdev/authorizer
(Go)
Apr 6, 2026
pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)
High
CVE-2026-35464
was published
for
pyload-ng
(pip)
Apr 4, 2026
BentoML: Command Injection in cloud deployment setup script
High
CVE-2026-35043
was published
for
bentoml
(pip)
Apr 3, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
High
CVE-2026-34172
was published
for
giskard-agents
(pip)
Mar 27, 2026
ProTip!
Advisories are also available from the
GraphQL API