GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
67 advisories
Filter by severity
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
High
CVE-2026-35511
was published
for
github.com/authorizerdev/authorizer
(Go)
Aug 14, 2026
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
High
CVE-2026-52845
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
High
CVE-2026-58423
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Gitea: Privilege Escalation via Access Token Scope Escalation in API
High
CVE-2026-56654
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
High
CVE-2026-55672
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
High
CVE-2026-55075
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
High
CVE-2026-55076
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
authentik's XML Signature Wrapping in SAML Source ACS allows authentication as arbitrary federated user
High
CVE-2026-47201
was published
for
goauthentik.io
(Go)
May 29, 2026
Crabbox: authentication bypass vulnerability that allows impersonation of others by spoofing identity headers
High
CVE-2026-8621
was published
for
github.com/openclaw/crabbox
(Go)
May 14, 2026
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
High
CVE-2026-42602
was published
for
github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
(Go)
May 6, 2026
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
High
CVE-2026-35579
was published
for
github.com/coredns/coredns
(Go)
Apr 28, 2026
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
High
CVE-2026-33190
was published
for
github.com/coredns/coredns
(Go)
Apr 28, 2026
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
High
CVE-2026-41145
was published
for
github.com/minio/minio
(Go)
Apr 14, 2026
MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads
High
CVE-2026-40344
was published
for
github.com/minio/minio
(Go)
Apr 14, 2026
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
High
CVE-2026-34727
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
High
CVE-2026-34204
was published
for
github.com/minio/minio
(Go)
Mar 27, 2026
Local Incus UI web server vulnerable to nuthentication bypass
High
CVE-2026-33898
was published
for
github.com/lxc/incus/v6/cmd/incus
(Go)
Mar 27, 2026
Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config
High
CVE-2026-32305
was published
for
github.com/traefik/traefik
(Go)
Mar 20, 2026
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
High
CVE-2026-32246
was published
for
github.com/steveiliop56/tinyauth
(Go)
Mar 12, 2026
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
Caddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege Escalation
High
CVE-2026-30851
was published
for
github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy
(Go)
Mar 6, 2026
ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication
High
CVE-2026-29193
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes
High
CVE-2026-30223
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
Antrea has invalid enforcement order for network policy rules caused by integer overflow
High
CVE-2026-25804
was published
for
antrea.io/antrea
(Go)
Feb 6, 2026
Gogs Vulnerable to 2FA Bypass via Recovery Code
High
CVE-2025-64175
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
ProTip!
Advisories are also available from the
GraphQL API