GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
19 advisories
Filter by severity
Buildah (as part of Podman) vulnerable to Path Traversal
Low
CVE-2022-4123
was published
for
github.com/containers/podman/v4
(Go)
Dec 8, 2022
Kubernetes vulnerable to path traversal
Moderate
CVE-2022-3162
was published
for
github.com/kubernetes/kubernetes
(Go)
Mar 1, 2023
Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server
Moderate
CVE-2023-40026
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 27, 2023
registry-support: decompress can delete files outside scope via relative paths
Moderate
CVE-2024-1485
was published
for
github.com/devfile/registry-support/registry-library
(Go)
Feb 14, 2024
Helm dependency management path traversal
Moderate
CVE-2024-25620
was published
for
helm.sh/helm/v3
(Go)
Feb 15, 2024
esm.sh has File Inclusion issue
High
CVE-2025-59341
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction
Critical
GHSA-rj4j-2jph-gg43
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Nov 24, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
High
CVE-2025-66626
was published
for
github.com/argoproj/argo-workflows
(Go)
Dec 9, 2025
apko has a path traversal in apko dirFS which allows filesystem writes outside base
High
CVE-2026-25121
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern
Critical
CVE-2025-62878
was published
for
github.com/rancher/local-path-provisioner
(Go)
Feb 4, 2026
Ory Oathkeeper has a path traversal authorization bypass
Critical
CVE-2026-33494
was published
for
github.com/ory/oathkeeper
(Go)
Mar 20, 2026
Source controller: Improper path handling allows traversal
Moderate
CVE-2026-47680
was published
for
github.com/fluxcd/source-controller
(Go)
Jun 5, 2026
Canonical MicroCeph: path traversal issue in the remote-import AP
Moderate
CVE-2026-10720
was published
for
github.com/canonical/microceph/microceph
(Go)
Jun 19, 2026
Gogs has Path Traversal in organization name that results in RCE through Git hooks
Critical
CVE-2026-52813
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
High
CVE-2026-48126
was published
for
github.com/xyproto/algernon
(Go)
Jun 23, 2026
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
High
CVE-2026-54066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API