GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
29 advisories
Filter by severity
gittuf's policy can be rolled back to prior valid versions
Moderate
CVE-2026-44544
was published
for
github.com/gittuf/gittuf
(Go)
May 7, 2026
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
Moderate
CVE-2026-42572
was published
for
github.com/hatchet-dev/hatchet
(Go)
May 6, 2026
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
Moderate
CVE-2026-44426
was published
for
github.com/shellhub-io/shellhub
(Go)
May 7, 2026
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
Moderate
CVE-2026-44423
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
Moderate
CVE-2026-44424
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
Velocidex Velociraptor has an authorization bypass vulnerability
Moderate
CVE-2026-7573
was published
for
www.velocidex.com/golang/velociraptor
(Go)
May 6, 2026
Focalboard doesn't validate file ownership when serving uploaded files
Moderate
CVE-2026-28736
was published
for
github.com/mattermost/focalboard
(Go)
Apr 3, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion
Moderate
CVE-2026-33700
was published
for
code.vikunja.io/api
(Go)
Mar 25, 2026
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments
Moderate
CVE-2026-33313
was published
for
code.vikunja.io/api
(Go)
Mar 20, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check
Moderate
CVE-2026-30886
was published
for
github.com/QuantumNous/new-api
(Go)
Mar 23, 2026
File Browser has an Authorization Policy Bypass in Public Share Download Flow
Moderate
CVE-2026-32761
was published
for
https://github.com/filebrowser/filebrowser
(Go)
Mar 18, 2026
Mattermost Boards Plugin fails to implement authorisation checks on comment block modifications
Moderate
CVE-2026-2461
was published
for
github.com/mattermost/mattermost-plugin-boards
(Go)
Mar 16, 2026
WeKnora has Unauthorized Cross‑Tenant Knowledge Base Cloning
Moderate
CVE-2026-30857
was published
for
github.com/Tencent/WeKnora
(Go)
Mar 6, 2026
Gogs Allows Cross-Repository Comment Deletion via DeleteComment
Moderate
CVE-2026-25120
was published
for
gogs.io/gogs
(Go)
Feb 17, 2026
Mattermost Server allows users with a session ID to revoke another users' session
Moderate
CVE-2017-18878
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Moderate
CVE-2022-31683
was published
for
github.com/concourse/concourse
(Go)
Oct 19, 2022
KubeSphere IDOR vulnerability
Moderate
CVE-2024-46528
was published
for
github.com/kubesphere/kubesphere
(Go)
Oct 14, 2024
Cache driver GetBlob() allows read access to any blob without access control check
Moderate
CVE-2024-39897
was published
for
zotregistry.dev/zot
(Go)
Jul 9, 2024
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures
Moderate
CVE-2024-40430
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Jul 22, 2024
•
withdrawn
Duplicate Advisory: Grafana vulnerable to authorization bypass
Moderate
GHSA-mh7p-8m2f-qrm6
was published
for
github.com/grafana/grafana
(Go)
Mar 26, 2024
•
withdrawn
Grafana API IDOR
Moderate
CVE-2022-21713
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
Go package pydio/cells vulnerable to authorization bypass
Moderate
CVE-2023-2978
was published
for
github.com/pydio/cells
(Go)
May 30, 2023
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4811
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
Authorization Bypass Through User-Controlled Key play-with-docker
Moderate
CVE-2023-28109
was published
for
github.com/play-with-docker/play-with-docker
(Go)
Mar 17, 2023
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4798
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
ProTip!
Advisories are also available from the
GraphQL API