Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

11 advisories

Loading
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection Moderate
GHSA-w253-m66g-rx24 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules Moderate
GHSA-3wr7-993q-jrff was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
airween Credited to airween and janmrow janmrow janmrow
Coraza has Cookie Parser Confusion Moderate
GHSA-g4qm-m288-5cp9 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
HackingRepo Credited to HackingRepo and fzipi fzipi fzipi
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations Moderate
GHSA-x26q-wvhg-fh4m was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection Moderate
GHSA-5gj4-9gm7-2fx2 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
netfoil has a domain name filter bypass via multiple questions Moderate
GHSA-59qp-cfj3-rp64 was published for github.com/tinfoil-factory/netfoil (Go) Jul 7, 2026
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters Moderate
CVE-2026-30246 was published for github.com/gofiber/fiber/v3 (Go) Apr 28, 2026
xeloxa Credited to xeloxa, gaby, and ReneWerner87 gaby gaby
ReneWerner87 ReneWerner87
Path Normalization Bypass in Traefik Router + Middleware Rules Moderate
CVE-2025-66490 was published for github.com/traefik/traefik (Go) Dec 8, 2025
ShadoooooW Credited to ShadoooooW
Gateway API route matching order contradicts specification Moderate
CVE-2024-42487 was published for github.com/cilium/cilium (Go) Aug 15, 2024
sayboras Credited to sayboras
btcd susceptible to consensus failures Moderate
CVE-2024-34478 was published for github.com/btcsuite/btcd (Go) May 5, 2024
Ethereum Contains Consensus Flaw During Block Processing Moderate
CVE-2021-39137 was published for github.com/ethereum/go-ethereum (Go) Aug 30, 2021
guidovranken Credited to guidovranken
ProTip! Advisories are also available from the GraphQL API