Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,347 advisories

Loading
File Browser: Colliding username normalization gives two users the same home directory High
CVE-2026-62685 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: Share API exposes the password hash and bypass token Low
CVE-2026-62684 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) Moderate
CVE-2026-62843 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
je-lv Credited to je-lv and hacdias hacdias hacdias
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope Moderate
CVE-2026-55668 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
DavidCarliez Credited to DavidCarliez and riodrwn riodrwn riodrwn
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup High
CVE-2026-55667 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
babakizo420 Credited to babakizo420 and lexdotdev lexdotdev lexdotdev
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses Moderate
CVE-2026-54562 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 20, 2026
baradika Credited to baradika and riodrwn riodrwn riodrwn
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim High
CVE-2026-54560 was published for github.com/cloudreve/Cloudreve/v4 (Go) Jul 20, 2026
EaEa0001 Credited to EaEa0001
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies High
GHSA-8qqm-fp2q-v734 was published for github.com/zalando/skipper (Go) Jul 17, 2026
Skipper's routesrv-no-auth component: All routesrv API Endpoints Lack Authentication Moderate
CVE-2026-54246 was published for github.com/zalando/skipper (Go) Jul 17, 2026
alcls01111 Credited to alcls01111
Gitea has insufficient permission checks for Composer package source links High
CVE-2026-27771 was published for code.gitea.io/gitea (Go) Jul 17, 2026
DevNoScope Credited to DevNoScope
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code Low
GHSA-rjwr-m7qx-3fjr was published for github.com/oapi-codegen/oapi-codegen/v2 (Go) Jul 17, 2026
quart27219 Credited to quart27219 and kimdu0 kimdu0 kimdu0
Skipper: Unbounded Request Body Read in Admission Webhook Causes Memory Exhaustion DoS Moderate
CVE-2026-54247 was published for github.com/zalando/skipper (Go) Jul 17, 2026
alcls01111 Credited to alcls01111
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-52724 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container Moderate
CVE-2026-52832 was published for github.com/nuclio/nuclio (Go) Jul 16, 2026
j311yl0v3u Credited to j311yl0v3u and b0b0haha b0b0haha b0b0haha
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE High
CVE-2026-52833 was published for github.com/nuclio/nuclio (Go) Jul 16, 2026
j311yl0v3u Credited to j311yl0v3u and b0b0haha b0b0haha b0b0haha
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode High
CVE-2026-53714 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
cnvergence Credited to cnvergence, zirain, guydc, and dashingDragon zirain zirain
guydc guydc dashingDragon dashingDragon
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure Critical
CVE-2026-53713 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
rudrakhp Credited to rudrakhp and dashingDragon dashingDragon dashingDragon
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock Moderate
CVE-2026-53715 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header Moderate
CVE-2026-53717 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization Moderate
CVE-2026-53719 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit Moderate
CVE-2026-53716 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
zhaohuabing Credited to zhaohuabing
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass Moderate
CVE-2026-53718 was published for github.com/envoyproxy/gateway (Go) Jul 16, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured Moderate
CVE-2026-50166 was published for github.com/kumahq/kuma (Go) Jul 16, 2026
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) Low
CVE-2026-58196 was published for github.com/stacklok/toolhive (Go) Jul 15, 2026
bIackr0se Credited to bIackr0se, jhrozek, JAORMX, ChrisJBurns, and rdimitrov jhrozek jhrozek
JAORMX JAORMX ChrisJBurns ChrisJBurns rdimitrov rdimitrov
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback High
CVE-2026-50285 was published for github.com/pomerium/pomerium (Go) Jul 15, 2026
bugbunny-research Credited to bugbunny-research
ProTip! Advisories are also available from the GraphQL API