Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

11 advisories

Loading
Ethereum Contains Consensus Flaw During Block Processing Moderate
CVE-2021-39137 was published for github.com/ethereum/go-ethereum (Go) Aug 30, 2021
guidovranken Credited to guidovranken
btcd susceptible to consensus failures Moderate
CVE-2024-34478 was published for github.com/btcsuite/btcd (Go) May 5, 2024
Gateway API route matching order contradicts specification Moderate
CVE-2024-42487 was published for github.com/cilium/cilium (Go) Aug 15, 2024
sayboras Credited to sayboras
Path Normalization Bypass in Traefik Router + Middleware Rules Moderate
CVE-2025-66490 was published for github.com/traefik/traefik (Go) Dec 8, 2025
ShadoooooW Credited to ShadoooooW
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters Moderate
CVE-2026-30246 was published for github.com/gofiber/fiber/v3 (Go) Apr 28, 2026
xeloxa Credited to xeloxa, gaby, and ReneWerner87 gaby gaby
ReneWerner87 ReneWerner87
netfoil has a domain name filter bypass via multiple questions Moderate
GHSA-59qp-cfj3-rp64 was published for github.com/tinfoil-factory/netfoil (Go) Jul 7, 2026
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection Moderate
GHSA-5gj4-9gm7-2fx2 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations Moderate
GHSA-x26q-wvhg-fh4m was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
Coraza has Cookie Parser Confusion Moderate
GHSA-g4qm-m288-5cp9 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
HackingRepo Credited to HackingRepo and fzipi fzipi fzipi
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules Moderate
GHSA-3wr7-993q-jrff was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
airween Credited to airween and janmrow janmrow janmrow
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection Moderate
GHSA-w253-m66g-rx24 was published for github.com/corazawaf/coraza/v3 (Go) Oct 8, 2026
MushroomWasp Credited to MushroomWasp
ProTip! Advisories are also available from the GraphQL API