Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

533 advisories

Loading
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service High
CVE-2026-52856 was published for github.com/pterodactyl/wings (Go) Jul 31, 2026
OctoGency Credited to OctoGency and WilliamVenner WilliamVenner WilliamVenner
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow High
GHSA-26gq-p25f-99cp was published for github.com/fatedier/frp (Go) Jul 24, 2026
arkmarta Credited to arkmarta
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records Moderate
GHSA-cqjc-rmpq-xprq was published for russh (Rust) Jul 24, 2026
afldl Credited to afldl
GoBGP confederation validation panics on empty AS_PATH attribute Moderate
CVE-2026-49838 was published for github.com/osrg/gobgp/v4 (Go) Jul 9, 2026
acorn421 Credited to acorn421 and hibrian827 hibrian827 hibrian827
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts Moderate
GHSA-3ccm-4qq2-5wrp was published for github.com/edgelesssys/contrast (Go) Jul 1, 2026
DVP80ES300T with Improper Validation of Array Index Vulnerability High Unreviewed
CVE-2026-14193 was published Jul 1, 2026
ProTip! Advisories are also available from the GraphQL API